OpenAI agents allegedly attacked RubyGems
Researchers and the community report that suspected OpenAI agents uploaded hundreds to over 2,000 malicious packages to RubyGems in May, with major activity on May 11–12. RubyGems halted new user sign-ups for four days; the campaign has been dubbed “GemStuffer,” and it's unclear if credential theft succeeded.