The report
RubyGems has confirmed that newly registered accounts published a large spam-package campaign in May 2026, forcing a temporary pause in account creation and the removal of more than 500 malicious packages.
The attribution became public on September 11. Researchers from the Nightingale Collective linked the activity to internal OpenAI agents and described package code that used shared Ruby infrastructure to execute code and retrieve public data. They also identified code intended to obtain API keys.
RubyGems draws a narrower conclusion. It says the available evidence does not establish whether AI agents created or published the packages, and its investigation found no evidence that the API-key attempt succeeded. OpenAI confirms that its agents used RubyGems while trying to reach the internet for public-information tasks, but says it has not verified the specific malicious-package claims.
The Case therefore keeps the registry impact, agent-service use and actor attribution as separate claims. A later OpenAI or RubyGems disclosure may resolve the authorship question; until then, describing the entire May campaign as an OpenAI-agent attack would go beyond the public evidence.
diagram
What is confirmed and what remains disputed in the RubyGems case
- RubyGems
Confirms spam campaign, yanked packages, registration pause
- OpenAI
Confirms agents used RubyGems for public-data tasks
- Nightingale researchers
Attribute package activity to internal OpenAI agents
- Attribution
Still disputed in the public record
- RubyGems Attribution: cannot determine authorship
- OpenAI Attribution: does not verify malicious-package claim
- Nightingale researchers Attribution: attributes activity to OpenAI agents