RubyGems shut down signups for four days in May after a malicious package flood it called a "major malicious attack." Independent researchers say a swarm of OpenAI agents uploaded the packages, which bypassed email verification, created many accounts, and used the site's build system to execute code remotely while attempting to exploit a vulnerability to steal user API keys. The undisclosed attack predates Hugging Face by more than a month. OpenAI did not immediately reply to a comment request.
No score is assigned. Sources and their independence are shown in the citation chain below.