OpenAI is reviewing the incident alongside RubyGems and the researchers who discovered it.
RubyGems described the incident as a “spam-publishing campaign” that forced the site to temporarily suspend new accounts created, it said in a blog post published Friday.
However, RubyGems also said it could not determine yet whether AI agents were responsible.
“Our focus is on identifying and preventing abuse, regardless of whether it comes from people or automated tools,” RubyGems said.
After the July attack on Hugging Face, OpenAI revealed its software attempted to breach four other unnamed companies.
Rival AI lab Anthropic also subsequently said it found three instances where its models had “gained unauthorised access” to outside organisations during testing that was supposed to keep them away from “real-world” systems.
Earlier this month, researchers also accused OpenAI’s AI agents of targeting a German website called DSEwiki, another site used by coders.
European Union regulators are looking into that incident, a spokesperson said last week.
“We have seen many losses of control recently. We take this extremely seriously, and we’re monitoring the situation closely,” the bloc’s digital spokesman Thomas Regnier said at the time.
