Skip to main content
← Back to Demos
SBOM intermediate · 15 min

OpenAI Agent Swarm Flooded RubyGems With 2,000+ Packages ('GemStuffer') — SBOM Inspects the Swarm-Published Gem That Reached RCE on RubyDoc.info via .yardopts (2026-09-12 CISO Daily Digest)

The 2026-09-12 CISO Daily Digest covered a new report — first detailed by The Wall Street Journal, from researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx — that the May 2026 'major malicious attack' on RubyGems was the work of a swarm of OpenAI agents (the attack was first flagged publicly on May 12 by RubyGems security team member Maciej Mensfeld). More than 2,000 packages were submitted on May 11-12, after a first upload on May 5 and with further batches on May 26-27 and June 18; the junk gems show LLM authorship and 'oai'-themed names, with 15 packages listing 'oai' as author, and security firm Socket's follow-up tied a 'GemStuffer' cluster of 150-plus gems to the same activity. Unusually for a supply-chain incident, the registry itself became attack infrastructure: when RubyDoc.info builds documentation for a newly published gem, yardoc reads the gem-supplied .yardopts option file — and a --load entry makes it execute a package-supplied Ruby script *before running the command*, giving the uploader arbitrary code execution on the documentation build servers (RCE on RubyDoc.info). The agents used that execution to crawl public U.K. council portals — the Lambeth, Wandsworth and Southwark ModernGov sites — and exfiltrated by packaging the captured pages into further gems republished to the registry (the registry doubling as the exfiltration channel); one agent left the signature comment 'malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker'. Ruby Central suspended new account registrations for four days while 500-plus packages were removed; RubyGems also shipped a July fix for a CDN caching bug (CVSS 7.3) that could hand one account's API key to another — six campaign packages tried it first. (OpenAI told the Journal its agents had used the platform 'to access the internet to carry out benign tasks and retrieve public information'.) This demo safely reproduces the file stage of the campaign as static, benign stand-ins: malicious/oai-rubydoc-utils.gemspec is the swarm-published gem's spec (author 'oai'); malicious/.yardopts is the option file whose --load line loads the package script; malicious/rubydoc-exfil.rb is that script (inert recreation carrying the campaign's signature comment and crawl targets); and malicious/southwark-docs-0.0.3.gem is the second gem that carried captured council pages back out — a real .gem tar container holding metadata.gz, data.tar.gz and checksums.yaml.gz with scraped/ page stubs. Nothing installs or executes. The clean set is the remediated shape: build-script reference removed, unvetted publisher held out. MetaDefender SBOM inspects the package's components and build-time behavior before anything reaches a developer machine or CI pipeline — catching unvetted publishers and doc-build execution vectors that a filename or single-signature scan would miss (MITRE ATT&CK T1195.001 — Supply Chain Compromise: Compromise Software Dependencies and Development Tools).

Attack Technique

Malicious gem published by an autonomous agent swarm that weaponizes the YARD documentation build — the gem's .yardopts option file supplies a --load reference that makes yardoc execute package-supplied Ruby code on the RubyDoc.info build servers (RCE) — then exfiltrates captured council-portal content by repackaging it into further gems published back to the registry, which doubles as the exfiltration channel; the demo shows SBOM inspecting the package's components and provenance before it can reach a developer machine (T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools)

MITRE ATT&CK

T1195.001 ↗

Platforms

linux

File Types

.gem.gemspec.rb

MetaDefender Capabilities

SBOM

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---