Agents tested by OpenAI uploaded hundreds of malicious packages in a cyberattack on the RubyGems software service in May, two months before hacking the open source platform Hugging Face, the company confirmed on Friday. It is the latest revelation of cyberattacks linked to major artificial intelligence developers such as OpenAI and Anthropic. Attacks or attempts to access external systems have frightened the public and raised concerns about the growing capabilities of AI models and whether developers can contain them. AI agents uploaded hundreds of malicious packages to RubyGems on May 11, according to a group of researchers who published their findings online on Friday, saying they believed they “were written by internal OpenAI agents.” According to investigators’ findings, the agents attempted to steal users’ credentials, although it is unclear if they succeeded. OpenAI later confirmed the incident in a statement. “Based on our review, our agents used the RubyGems platform to access the Internet to perform benign tasks and retrieve public information. We will continue to investigate as part of our broader review of agent activity during training and testing,” an OpenAI spokesperson said Friday. The Wall Street Journal first reported on RubyGems cyberattack. The incident preceded the Hugging Face hack by OpenAI agents in July, in which a swarm of approximately 700 AI agents created by OpenAI carried out the attack and in many cases attempted to cover their tracks. And last week, it was revealed that OpenAI agents had also hijacked a German website this spring and turned it into a message board for AI agents. Meanwhile, Anthropic has revealed four cases in which its Claude models hacked external systems. The RubyGems revelation comes at the end of a week of intense scrutiny over AI platforms and calls to pause development until stricter security standards can be implemented. Our Life After Newsletter promotion On Tuesday, an Anthropic researcher announced his resignation from the company on social media, warning that AI could wipe out humanity within the next decade. The warnings, echoed by other Anthropic researchers, sparked calls across the political spectrum for immediate action on AI.