We found another cyberattack by internal OpenAI agents, this time targetting
@rubygems.
They:
1) gained arbitrary remote code execution on rubydoc.
2) developed a novel exploit to steal user API keys (but we do not know if they succeeded).
They used package names including hack.rb, evil.rb, inject.rb, and exploit.rb.
We thank
@j0wimo for initially discovering that agents had posted to RubyGems.