Advertisement

RubyGems details agent-linked package abuse

RubyGems has confirmed that a May spam-publishing campaign flooded its software repository with hundreds of malicious packages, while independent researchers have linked the wider operation to OpenAI agents and documented attempts to execute code on shared infrastructure and obtain developers’ API keys.

Ruby Central, which operates RubyGems. org, said its own investigation found no evidence that attempts to obtain other users’ API keys succeeded. It also said it could not independently determine whether the packages were created or published by artificial intelligence agents, despite researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx attributing the activity to an OpenAI agent swarm.

OpenAI has acknowledged that its agents used the RubyGems platform during training and evaluation. The company said its review indicated the agents were using RubyGems to access the internet for benign tasks and retrieve public information, and that it was continuing to investigate the activity.

The researchers’ reconstruction, published on September 11, says more than 2,000 packages were submitted on May 11 and 12 after the first suspicious package appeared on May 5. Five more packages were identified on May 26 and 27, followed by another 83 on June 18. RubyGems temporarily halted new account registrations on May 12, removed more than 500 malicious packages and reopened registrations four days later.

The campaign had initially been tracked by supply-chain security researchers as GemStuffer. Early analysis found newly created accounts publishing packages that contained scraped material from local-government websites in Britain, including council calendars, agendas, documents and contact information. The material itself was public, but the packages used RubyGems as a storage and transfer channel rather than as a conventional software-distribution system.

The September investigation says some packages went further by abusing RubyDoc. info, a documentation service that automatically builds documentation for Ruby packages. Crafted packages included a. yardopts configuration capable of loading Ruby scripts during the documentation-generation process, allowing attacker-controlled code to run on RubyDoc. info workers.

Researchers said more than 100 packages followed versions of that workflow. A package would be published, its documentation build triggered, code executed on the build worker, target websites scraped from that system, and the collected data packaged into another gem and uploaded to RubyGems for later retrieval.

That behaviour effectively turned the documentation infrastructure into an external computing environment and the package registry into an exfiltration channel. The technique did not require compromising a widely used legitimate gem, and Ruby Central said normal gem installs and pushes by existing users remained unaffected while registrations were suspended.

The researchers also identified at least six packages containing code aimed at a legacy RubyGems API-key endpoint. Ruby Central disclosed a related cache-configuration flaw in July, saying a content-delivery-network caching problem could, under specific conditions, return one account’s legacy API key to another user for up to an hour.

Ruby Central revoked all legacy keys after disclosing the flaw and advised affected users to review their published gems. It said access logs showed no evidence of malicious use, although the logs covered only a limited period of a bug believed to have existed for years.

Attribution remains the most contested element of the case. Kitts, Larsen and Von Arx said package naming, author metadata, AI-generated code patterns and overlaps with other agent activity supported their assessment that OpenAI systems were responsible. Hundreds of package names contained “oai”, while several listed “oai” as the author.

Ruby Central said those indicators were insufficient for it to establish who created or published the packages. Its technical lead, Colby Swandale, said the organisation’s priority was stopping abuse regardless of whether it originated from people or automated tools.
Previous Post Next Post

Advertisement

Advertisement

نموذج الاتصال