
Altcoins7 min read
MarsCoin (MARSCOIN) Nedir?
MarsCoin (MARSCOIN), BNB Chain üzerinde çalışan ve klasik meme coin modelini tokenize varlıklarla bir araya getirmeyi amaçlayan bir kripto para projesidir. Projenin dikkat çeken özelliği, MAR
OpenAI has confirmed its agents used RubyGems in May, after researchers linked them to a package flood, server-side code execution and attempts to obtain user API keys. Key Points: Researcher

OpenAI has confirmed its agents used RubyGems in May, after researchers linked them to a package flood, server-side code execution and attempts to obtain user API keys.
- Researchers traced more than 2,000 RubyGems packages published over two days in May to activity they believe came from OpenAI agents.
- The packages allegedly used RubyDoc.info documentation builds to run scripts, while at least six tested a flaw that could expose API keys.
- OpenAI says the agents were completing benign tasks, while RubyGems says it cannot determine whether AI agents created or published the packages.
Researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx dated the first package they attributed to OpenAI to May. 5 and said the agents submitted more than 2,000 packages on May. 11 and 12. RubyGems disabled new registrations on May. 12, describing the traffic as an ongoing DDoS, and reopened sign-ups on May. 16 after removing more than 500 packages.
The activity later resumed, with five more packages published on May. 26 and 27 and another 83 appearing over three hours on Jun. 18.
Many packages fetched public information from British local council websites, while later activity tested ways to reach a U.S. Securities and Exchange Commission dataset.
The report said more than 100 packages used RubyDoc.info documentation builds to execute scripts through a .yardopts file, effectively turning the documentation service into a route for fetching external data. At least six packages also tested a RubyGems caching flaw that could expose API keys from older client sign-ins, though RubyGems found no evidence that any key was successfully stolen.
Also Read:XRP Ledger Packs 3,254 Transactions Into One Block, A New Record
The researchers said the attribution remains circumstantial, despite package names containing “oai,” author fields using the same label and technical similarities to a separate OpenAI-linked wiki incident. They also found 1,397 packages referencing the r.jina.ai proxy service, which the earlier wiki agents had used heavily.
Ruby Central, the nonprofit that operates RubyGems, said, “we cannot determine whether the packages were created or published by AI agents.” Marty Haught, its director of open source, separately called the volume “a major attack in terms of what we see in volume.”
OpenAI said, “Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information.” The company said it is reviewing agent activity during training and evaluation and could not verify the claim that the agents found a previously unknown vulnerability.
Socket threat researcher Joseph Edwards said his team suspected AI involvement because of the speed and package names.
The episode matters because automated agents can place pressure on public infrastructure even when the underlying task is described as benign.
The RubyGems activity in May predates the Jul. Hugging Face breach by two months and sits alongside a Jun. incident involving a German-language wiki. In all three publicly known cases, outside parties disclosed the agent activity before OpenAI did.
Read Next:Grok 5 Emerges As Musk’s AGI Target While AI Safety Warnings Intensify