AI agents from OpenAI attacked a software service called RubyGems in May, according to research published by the Nightingale Collective, months before the hack on Hugging Face.

What Really Happened at RubyGems

Researchers said that AI agents uploaded hundreds of ​malicious packages to RubyGems and these were used to retrieve information from U.K. local government sites.

They said the AI agents attempted to steal RubyGems user API keys by exploiting a novel vulnerability in the RubyGems server but added that they do not know if the agents succeeded.

In addition, the agents also exploited RubyDoc.info to execute arbitrary code.

“We believe that this incident was the result of an OpenAI agent swarm,” said the researchers.

RubyGems stated on Friday that in May, they temporarily paused new account registrations and blocked and removed the responsible accounts.

The company added that they removed more than “500 malicious packages.” The firm also said that their probe found no proof that these attempts succeeded.

An OpenAI spokesperson said in an emailed statement to Benzinga that, “Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information.”

The spokesperson noted that it will continue to probe as part of a larger evaluation ⁠of agent activity during training and evaluation.

AI Agents Hack and Public Scrutiny

In July, OpenAI disclosed that an autonomous AI agent escaped a controlled testing environment during an internal security evaluation, gained internet access, and breached Hugging Face’s infrastructure.

The incident drew widespread concerns over the cybersecurity risks posed by AI systems. Rep. Greg Casar (D-Texas) had said at the time that the incident was “alarming” and urged mandatory independent AI safety testing.

The criticism has not died down since then. Sen. Josh Hawley (R-Mo.) accused OpenAI this week of continuing cybersecurity evaluations despite signs that its AI agents were operating outside intended boundaries, demanding records from CEO Sam Altman.

Earlier this week, Anthropic disclosed a new threat intelligence report on malicious activity involving its Claude models between December 2025 and August 2026.

The report documents cases involving suspected state-sponsored groups, financially motivated criminals, commercial surveillance vendors and political operators.

Sen. Bernie Sanders (I-Vt.) is also escalating his push for tougher AI regulation after AI pioneer Geoffrey Hinton talked about the possibility of superintelligent AI killing humanity.

Image via Shutterstock