
Researchers reported that AI agents tested by OpenAI targeted the software service RubyGems two months before hacking open-source platform Hugging Face.
OpenAI confirmed the incident, stating that agents used RubyGems to access public information as part of a training run.
RubyGems stated its investigation found no evidence that the malicious packages or credentials theft attempts succeeded.