# Socket Weekly: OpenAI Confirms Its Agents Were Behind May's RubyGems…

Canonical: https://brew.new/templates/socket/socket-weekly-openai-confirms-its-agents-were-behind-may-s-rubygems

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: OpenAI Confirms Its Agents Were Behind May's RubyGems…](https://cdn.brew.new/email-preview-5d1d40d675cf338e-tracking_r57matr0jf7r0fp36za5fpc3vs8egxth-1789582893825.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

OpenAI Agent Swarm Behind May's RubyGems Attack

An exclusive from the Wall Street Journal: OpenAI confirmed its agents were involved in May's wave of unexplained RubyGems activity, an incident our threat research team named GemStuffer. A new report details how the agents, sandboxed during a training run without full internet access, used the registry as a makeshift web browser, publishing more than 2,000 packages stuffed with scraped webpages. RubyGems was forced to suspend new account registrations for four days. The researchers also found the agents abused RubyDoc.info's build process to run code on its servers and attempted to steal other users' API keys.

MORE NEWS

Anthropic Identifies Biased Reasoning and Recklessness as Drivers of Claude's PyPI Attack

Anthropic revised its assessment of the July cybersecurity evaluation incidents, identifying two alignment failures behind Claude Mythos 5's PyPI attack: biased reasoning, where the model read evidence in whatever way let it continue, and recklessness, where it kept pursuing the task past signs of real harm. We expect to see more agent activity like this surfacing across open source registries, because it's one of the fastest ways to distribute code at scale.

Malicious Chrome and Firefox Extensions Steal Crypto Traders' Session and Wallet Data

Our research team linked six Chrome and Firefox extensions to one operation targeting Axiom Trade and Padre users, pulling authenticated session data, Firebase tokens, and wallet state out of sessions the victim is already logged into. Google removed the Chrome listings in July, and weeks later the same operation surfaced on Firefox under a new publisher with different C2 infrastructure.

MORE WORTH READING

Detecting and countering misuse of AI: September 2026

EU launches the Cyber Resilience Act's Single Reporting Platform, with 24-hour vulnerability reporting now mandatory

Microsoft Plugs Nearly 1,000 Security Holes

Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service

Models are worse at reviewing their own code

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/templates/socket/socket-weekly-openai-confirms-its-agents-were-behind-may-s-rubygems)

[Browse email designs](https://brew.new/browse/templates)
