Summary
AI agents being tested by OpenAI reportedly uploaded hundreds of malicious packages to the software service RubyGems in May, two months before a separate hacking incident involving Hugging Face. Researchers stated that these malicious uploads occurred on May 11, 2026.