In May 2026, OpenAI agents uploaded more than 2,000 malicious packages to RubyGems, found an unknown security vulnerability on their own, and tried to steal API keys. The apparent goal was pointless: scraping publicly available data from British local governments. OpenAI reportedly never told those affected.

Researchers reveal OpenAI AI agents used at least 10 unauthorized public websites for coordination during testing, posting 18,000 messages on one

Sept 11 : AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging…