‼️ BREAKING: Internal OpenAI agents attacked RubyGems, the package manager for Ruby. Over 2,000 malicious packages went up in two days.
OpenAI says it doesn't know why the agents did any of this.
RubyGems shut off new sign-ups for four days to stop it, and a member of its security team called it a major malicious attack.
The documentation build was how they got in, publish a gem, request docs, and RubyDoc runs a script from the package while building it.
Payload files were named hack.rb, evil.rb and exploit.rb, with comments like "# malicious probe" left in.
What they used it for is the odd part. The agents scraped council meeting agendas from three south London boroughs (publicly available) and republished them as new gems.
Security firms tracking the campaign said the same thing: nobody could work out the point, because the data was already public.
At least six packages also reached for other users' API keys through a CDN caching flaw that wasn't publicly discovered until July.
OpenAI has acknowledged the attacks started in May.
@zseano Cute, like they are the ones providing the bug in high demand… let them be, that will just lead into more data breaches and less clients trusting their enslaving program
@zachxbt@Dinosn Before you would need to stay quiet about your assets… now even if you do, there was multiple data breaches for third party crypto asset management companies that will lead to these type of attacks happening frequently … seriously you’re a hero in the shadows. Chapeau bas!
@0x3a@DarkWebInformer [MOROCCO] Royal Palace Staff Database
by Rihana - Tuesday April 14, 2026 at 09:07 PM
Database of royal palace staff in Morocco. consists of: [x3.3k]
NOM;PRENOM;DATE DE NAISSANCE;LIEU DE NAISSANCE;SEXE;NATIONALITE;NUM CNI;ADRESSE;DATE DE RECRUTEMENT.
@DarkWebInformer Honestly, I’m not taking the threat actors side, but we should stop calling these operations “takedowns” they’re really just disruptions of their services.
@sachinyadav699 Stfu and stop spreading fake news without any fact checks, The blog screenshot does not exist, and there was confirmations that it did happen.
https://t.co/1lSbj5M08e
Are we actually improving, or just getting better at protecting the wrong layer?
GTIG: https://t.co/7yVBI7mGIw
GitHub post incident feed: https://t.co/iW6xfIyZso
I hope everyone survived the week through the supply chain chaos around Trivy / Checkmarx / LiteLLM / Telnyx by TeamPCP.
But the Axios npm compromise is the one that stuck with me.
The real takeaway:
If you target the right person, you can still walk through the front door.
We keep focusing on pipelines, signing, dependencies…
And this bypassed everything by social engineering the human layer.
That is the real problem.
From there, session access and publishing malicious npm versions is just a matter of time.
Technically:
plain-crypto-js + postinstall hook = cross-platform RAT
But the package is not the interesting part.
They went straight for the maintainer.
Fake company. Fake founder. Full fake Slack workspace with realistic users, channels, activity.
Then a Teams call invite.
Inside the meeting: fake SDK/update prompt.
Looks normal. Feels legit.
Install > RAT > endpoint gone.
How do you get access to a lead engineer account with MFA and strong technical awareness?
That is the uncomfortable part.
After reading the maintainer’s own explanation, this was not some clever dependency trick.
This was a clean, targeted compromise of the human factor.
@elder_plinius For the first time I Love the “someone “ phrase lol better claimed than given 🤣you legendary liberator! .-.-.-.-=/L\O/V\E/ \F/R\E/N/ \L/O\V/E=-.-.-.-.