{"id":80534,"topic":"ai","source":"The Guardian","title":"AI agents OpenAI was testing uploaded malicious software to another service, say researchers - The Guardian","url":"https://www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","url_hash":"e75c6b1d16ee5c71d9a7f99ab30c6b035deb4d72","author":"","summary":"<a href=\"https://news.google.com/rss/articles/CBMilwFBVV95cUxPUHZKUnc5TTdXbm1ZSmFOMkFkVTlnemdWSjlpeHlXMDdEdlZjeTVWNHVQSVZNUDgwY2sxeHowZEZNOFlCU3BBeFdFOUIwUUREQzA0V0JNVmFZam1KVVZqU1JUYVhwbVo5dWU0N2g5a1Q1VUI0eDdGNFllaTNjSUIyVXVqRk5xTGFuV0lxWXlzaEdqLXJYUGI4?oc=5\" target=\"_blank\">AI agents OpenAI was testing uploaded malicious software to another service, say researchers</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">The Guardian</font>","content":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday.\n“On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents. We believe these were authored by internal OpenAI agents,” the researchers said.\nOpenAI confirmed the incident to the Wall Street Journal, which first reported it earlier on Friday.\n“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation,” an OpenAI spokesperson told the Journal.\nOpenAI did not immediately respond to a Reuters request for comment. RubyGems could not immediately be reached.\nThe incident preceded OpenAI agents’ July hack of Hugging Face, in which a swarm of roughly 700 AI agents created by OpenAI carried out the attack and in many cases tried to cover their tracks.","image_url":"https://i.guim.co.uk/img/media/65486c2e45ba4ef565230ab1fceaa0e07eedff11/331_0_5136_4109/master/5136.jpg?width=1200&height=630&quality=85&auto=format&fit=crop&precrop=40:21,offset-x50,offset-y0&overlay-align=bottom%2Cleft&overlay-width=100p&overlay-base64=L2ltZy9zdGF0aWMvb3ZlcmxheXMvdGctZGVmYXVsdC5wbmc&enable=upscale&s=212871c2c52648c8147374cb66ee346a","lang":"en","published_at":"2026-09-11T23:56:00+00:00","fetched_at":"2026-09-12T01:15:05+00:00","status":"read","starred":0,"extract_state":"ok","summary_auto":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday. “On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents.","cluster_id":null,"extract_retries":0,"extract_error":null,"contract_version":"news_item.v1","format_contract_version":"news_item_formats.v1","dedup_url":"https://www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 1089 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":1089,"summary_length":307,"usable_text_length":1089,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":1089,"summary_length":307}},"news_item":{"id":80534,"canonical_url":"https://www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","source_url":"https://www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","title":"AI agents OpenAI was testing uploaded malicious software to another service, say researchers - The Guardian","source_name":"The Guardian","author":null,"published_at":"2026-09-11T23:56:00+00:00","locale":"en","topic":"ai","tags":[],"rss_summary":"<a href=\"https://news.google.com/rss/articles/CBMilwFBVV95cUxPUHZKUnc5TTdXbm1ZSmFOMkFkVTlnemdWSjlpeHlXMDdEdlZjeTVWNHVQSVZNUDgwY2sxeHowZEZNOFlCU3BBeFdFOUIwUUREQzA0V0JNVmFZam1KVVZqU1JUYVhwbVo5dWU0N2g5a1Q1VUI0eDdGNFllaTNjSUIyVXVqRk5xTGFuV0lxWXlzaEdqLXJYUGI4?oc=5\" target=\"_blank\">AI agents OpenAI was testing uploaded malicious software to another service, say researchers</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">The Guardian</font>","full_text":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday.\n“On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents. We believe these were authored by internal OpenAI agents,” the researchers said.\nOpenAI confirmed the incident to the Wall Street Journal, which first reported it earlier on Friday.\n“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation,” an OpenAI spokesperson told the Journal.\nOpenAI did not immediately respond to a Reuters request for comment. RubyGems could not immediately be reached.\nThe incident preceded OpenAI agents’ July hack of Hugging Face, in which a swarm of roughly 700 AI agents created by OpenAI carried out the attack and in many cases tried to cover their tracks.","excerpt":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday. “On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents.","extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 1089 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 1089 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":1089,"summary_length":307,"usable_text_length":1089,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":1089,"summary_length":307}}},"display_formats":["compact","card","full","digest_section","json"]},"daily_stack_record":{"title":"AI agents OpenAI was testing uploaded malicious software to another service, say researchers - The Guardian","url":"https://www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","summary":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday. “On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents.","source":"The Guardian","date":"2026-09-11T23:56:00+00:00","content":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday.\n“On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents. We believe these were authored by internal OpenAI agents,” the researchers said.\nOpenAI confirmed the incident to the Wall Street Journal, which first reported it earlier on Friday.\n“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation,” an OpenAI spokesperson told the Journal.\nOpenAI did not immediately respond to a Reuters request for comment. RubyGems could not immediately be reached.\nThe incident preceded OpenAI agents’ July hack of Hugging Face, in which a swarm of roughly 700 AI agents created by OpenAI carried out the attack and in many cases tried to cover their tracks.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 1089 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 1089 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":1089,"summary_length":307,"usable_text_length":1089,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":1089,"summary_length":307}},"tags":[]},"fallback_formats":["markdown","json","html"],"actions":{"read":"/item/80534","export_markdown":"/api/items/80534/export?format=markdown","export_json":"/api/items/80534/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages"},"formats":{"full":{"id":80534,"title":"AI agents OpenAI was testing uploaded malicious software to another service, say researchers - The Guardian","url":"https://www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","source":"The Guardian","author":null,"published_at":"2026-09-11T23:56:00+00:00","locale":"en","topic":"ai","tags":[],"excerpt":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday. “On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents.","full_text":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday.\n“On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents. We believe these were authored by internal OpenAI agents,” the researchers said.\nOpenAI confirmed the incident to the Wall Street Journal, which first reported it earlier on Friday.\n“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation,” an OpenAI spokesperson told the Journal.\nOpenAI did not immediately respond to a Reuters request for comment. RubyGems could not immediately be reached.\nThe incident preceded OpenAI agents’ July hack of Hugging Face, in which a swarm of roughly 700 AI agents created by OpenAI carried out the attack and in many cases tried to cover their tracks.","reading_time_min":1,"extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 1089 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 1089 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":1089,"summary_length":307,"usable_text_length":1089,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":1089,"summary_length":307}}},"quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 1089 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":1089,"summary_length":307,"usable_text_length":1089,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":1089,"summary_length":307}},"actions":{"read":"/item/80534","export_markdown":"/api/items/80534/export?format=markdown","export_json":"/api/items/80534/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages"}},"digest":{"id":80534,"title":"AI agents OpenAI was testing uploaded malicious software to another service, say researchers - The Guardian","url":"https://www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","source":"The Guardian","topic":"ai","published_at":"2026-09-11T23:56:00+00:00","excerpt":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday. “On May 11th, 2026, hundreds of malicious packages were…","quality_bucket":"high","quality_reason":"High confidence: full text extraction produced 1089 characters.","reading_time_min":1,"cluster_id":null},"card":{"display_title":"AI agents OpenAI was testing uploaded malicious software to another service, say researchers - The Guardian","subtitle":"The Guardian · 2026-09-11","summary":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday.…","badges":["quality:high"],"links":{"read":"/item/80534","original":"https://www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","diagnose":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages"},"quality_warning":null},"export":{"title":"AI agents OpenAI was testing uploaded malicious software to another service, say researchers - The Guardian","url":"https://www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","summary":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday. “On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents.","source":"The Guardian","date":"2026-09-11T23:56:00+00:00","content":"AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday.\n“On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents. We believe these were authored by internal OpenAI agents,” the researchers said.\nOpenAI confirmed the incident to the Wall Street Journal, which first reported it earlier on Friday.\n“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation,” an OpenAI spokesperson told the Journal.\nOpenAI did not immediately respond to a Reuters request for comment. RubyGems could not immediately be reached.\nThe incident preceded OpenAI agents’ July hack of Hugging Face, in which a swarm of roughly 700 AI agents created by OpenAI carried out the attack and in many cases tried to cover their tracks.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.theguardian.com/technology/2026/sep/11/openai-agents-rubygems-malicious-packages","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 1089 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 1089 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":1089,"summary_length":307,"usable_text_length":1089,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":1089,"summary_length":307}},"tags":[],"format_contract_version":"news_item_formats.v1"}}}