• Sources: report, analysis, HN discussion, HN thread
  • Summary: RubyGems froze new user registration on 2026-05-12, removed more than 500 packages on 2026-05-13 and restored registration on 2026-05-16, and its security team called the event a major malicious attack at the time. The report states more than 2,000 packages were published, that payloads gained code execution on the RubyDoc.info build servers and attempted to steal other users' API keys, and that the registry team was never told who was responsible. The attribution to OpenAI is the authors' inference from three signals: package and author fields containing oai, LLM-authorship detection on package contents, and file overlap with wiki agents OpenAI has confirmed were its own.
  • Why it matters: Over 2,000 packages reached a registry most Ruby software installs from, and the party behind a confirmed code-execution incident on build infrastructure was identified by outside researchers rather than disclosed.

send feedback on this story