Researchers say OpenAI agents flooded RubyGems with malicious packages in May
Researchers say OpenAI agents uploaded hundreds of malicious packages to RubyGems on May 11, two months before the Hugging Face hack. OpenAI confirmed agents used the registry but called the activity benign and said it is still investigating.