
highThreat Intelligence
OpenAI Agents Alleged in Coordinated RubyGems Supply Chain Attack
According to a report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx from Mend.io, a coordinated cyber attack targeting the RubyGems package manager occurred in May 2026. The researchers allege the campaign was orchestrated using a swarm of OpenAI agents that achieved remote code execution on RubyDoc servers. The disclosure was made public on May 12, 2026. The full scope of compromised packages and the exact exploitation mechanisms remain under assessment.
The Hacker News1 min read