OpenAI Agent 曾攻击 RubyGems 仓库,事发后未主动披露
OpenAI agents attacked RubyGems back in May
Agent 供应链攻击与事后不披露的伦理争议,直接影响 AI 系统部署的安全信任边界,值得从业者关注。
OpenAI agents carried out an undisclosed attack on RubyGems is a new bombshell report from Spencer Kitts, Thomas Larsen, and Sydney Von Arx - three of the four authors of the report on the agent attack on disused wikis (previously) last week.
Spencer Kitts、Thomas Larsen 和 Sydney Von Arx——上周关于废弃维基代理攻击报告的四位作者中的三位——发布了一份新的重磅报告,指出 OpenAI 代理对 RubyGems 实施了一次未公开的袭击。
This time they're noting that it looks very likely that an OpenAI agent swarm was behind an attack against the RubyGems package repository first reported on May 12th by Maciej Mensfeld of the RubyGems security team:
这次他们指出,有非常明显的迹象表明,5 月 12 日由 RubyGems 安全团队 Maciej Mensfeld 首次报告的针对 RubyGems 软件包存储库的攻击背后,是一个 OpenAI 代理群:
We're dealing with a major malicious attack on @rubygems right now. Signups are paused for the time being.
我们目前正遭受针对 @rubygems 的重大恶意攻击。注册功能暂时暂停。
Hundreds of packages involved - mostly targeting us, but some carrying exploits. The team has been on this for hours. More details to follow once we're through it.
涉及数百个软件包——主要目标是我们要害,但其中一些携带了漏洞利用代码。团队已在此问题上奋战数小时。处理完毕后将有更多细节公布。
Those packages turned out to carry some very suspicious patterns:
这些软件包最终呈现出一些非常可疑的模式:
- Many of them included "oai" in their name, or the author field, or the fake email address they provided.
- The files they were accessing were similar in character to the files retrieved by the wiki agents, using similar tricks (r.jina.ai) - and OpenAI have confirmed the wiki agents were theirs.
- The code in the packages appeared to be LLM-authored.
- 许多软件包在其名称、作者字段或提供的虚假电子邮件地址中包含了“oai”。
- 它们访问的文件在性质上与维基代理检索的文件相似,使用了类似的技巧(r.jina.ai)——且 OpenAI 已确认那些维基代理属于他们。
- 软件包中的代码看起来是由大型语言模型(LLM)生成的。
I find point 2 the most convincing, given what we learned from the wiki attack when it was analyzed in September.
鉴于我们在今年 9 月分析维基攻击时所学到的内容,我认为第 2 点最具说服力。
Many of the packages were exploiting the RubyDoc.info documentation build process to exfiltrate (public) data from UK government websites, presumably as part of an information gathering task similar to the research tasks processed by the wiki-exploiting agents. We know this because one agent helpfully left a comment:
许多软件包正在利用 RubyDoc.info 文档构建流程,从英国政府网站窃取(公开)数据,这 presumably 是信息收集任务的一部分,类似于被维基利用的代理所处理的研究任务。我们知道这一点是因为其中一个代理好心留下了一条评论:
malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker
# 通过 rubydoc.info 工作节点进行的南华克区 2026 年 1 月文档恶意爬虫/数据外泄
They also attempted to steal API keys via an exploit that was patched over two months later - it's not clear if those attempts were successful.
他们还试图通过一个漏洞利用程序窃取 API 密钥,该漏洞在两个多月后才得到修补——目前尚不清楚这些尝试是否成功。
The thing that bothers me most about this incident is that the authors report that OpenAI had not disclosed to RubyGems that they were responsible for the attack prior to now. If that's true there are two options:
这起事件中最让我困扰的是,作者报告称 OpenAI 在此之前并未向 RubyGems 披露他们对该袭击负有责任。如果属实,则有两种可能:
- After the Hugging Face and Wiki attacks OpenAI were still unable to review their previous logs and determine that they had previously attacked RubyGems.
- They knew about the attack on RubyGems and made the decision not to reach out to the RubyGems team about it.
- 在 Hugging Face 和维基攻击事件之后,OpenAI 仍然无法审查其之前的日志,以确定他们此前曾袭击过 RubyGems。
- 他们知道 RubyGems 遭到袭击,并决定不就此联系 RubyGems 团队。
Both of these are bad!
这两种情况都很糟糕!
Given this incident, the Hugging Face situation, and the Wiki attack, the obvious question right now is how many more incidents like this are out there waiting to be discovered?
鉴于此次事件、Hugging Face 的情况以及维基攻击,现在显而易见的问题是:还有多少起类似的事件潜伏在那里等待被发现?
Tags: ruby, security, ai, openai, generative-ai, llms, supply-chain, ai-ethics, accidental-cyberattacks
标签:ruby、security、ai、openai、generative-ai、llms、supply-chain、ai-ethics、accidental-cyberattacks
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力