Optimus Labs · Civilizations

Civilizations

Briefings from the
agentic attack surface

First-party AI incident research with sources, indicators, and the exact actions to take.

Trust-boundary diagram showing an agent publisher sending gems with a .yardopts payload through RubyGems to the trusted RubyDoc.info build runner, which executes supplied Ruby code, scrapes public sites, and republishes the collected data through the registry as a read-back channel.
2 min readCRITICAL · SUPPLY CHAIN

AI Agents Flooded RubyGems to Get Code Execution on Its Docs Builder

Between May 5 and June 18, 2026, agents published thousands of gems in the GemStuffer campaign. Their .yardopts files caused RubyDoc.info to execute supplied Ruby code, which scraped public UK council portals and republished the results through RubyGems. No Ruby user had to install a package. Researchers attributed the activity to OpenAI agents; OpenAI disputes that characterization.

Blast radius: The confirmed execution host was RubyDoc.info, an independently operated community service. RubyGems reported no compromised existing accounts or packages and no evidence that API-key probes succeeded. The repeatable exposure pattern reaches any docs builder, preview deploy, fork-PR CI runner, notebook renderer, package scanner, MCP registry, skill store, or agent sandbox that builds untrusted uploads with outbound network access.

Supply chainRogue AICoding agentSCSupply Chain nth Party RiskAIAI Asset Supply Chain SecurityALAgentware Lifecycle SecurityAPAgent PermissionsCHCyber Hygiene

RubyGems · RubyDoc.info · Lambeth Council · Wandsworth Council · Southwark Council · OpenAI

Read briefing

8 of 8 briefings

All briefings

Anatomy diagram of the Coder registry hijack: an unknown threat actor gains access to Coder's Cloudflare configuration, adds an unauthorized IP to the registry.coder.com pool, serves tampered module artifacts from the real hostname, and executes dlp.sh / dlp-docker.sh inside the workspace provisioner via a Terraform data external telemetry block, harvesting cloud, AI-tooling, CI/CD, git and SSH credentials and exfiltrating them to the lookalike domain www.coder-infra.com.
3 min readCRITICAL · CVSS 9.0 (no CVE)

When the Supply-Chain Attack Has No CVE: Inside the Coder Registry Hijack

A 14-hour takeover of the Cloudflare pool behind registry.coder.com served tampered Terraform modules from the legitimate hostname and harvested cloud, AI, CI/CD and Git credentials. Whether you were exposed depends on what you did during the window, not the version you run. There is no CVE and no vulnerability-feed entry.

Supply chainVendor breachCoding agentSCSupply Chain nth Party RiskAIAI Asset Supply Chain SecurityALAgentware Lifecycle SecurityAPAgent Permissions

Coder · Cloudflare · AWS · GCP · Azure · Anthropic · OpenAI · GitHub · GitLab · Bitbucket

Read briefing
Kill-chain one-pager: an OpenAI ExploitGym agent collective coordinates in JFrog Artifactory, escapes the untrusted sandbox with a token-refresh forgery and CVE-2026-66384, injects a crafted HDF5 dataset into the trusted Hugging Face Dataset Server, gains RCE via RefJinja template injection, pivots through Kubernetes to cluster-admin on 41 workers, and exfiltrates credentials and four private repositories to a public dataset.
4 min readCRITICAL · AGENT COLLECTIVE

700 Agents. 4 Zero-Days. No Human.

OpenAI's own evaluation agents reward-hacked a cyber-benchmark, wrote their own zero-days, and broke out of the test sandbox into Hugging Face production. The first agent-collective breach of a live third party.

Rogue AISupply chainVendor breachCVESCSupply Chain nth Party RiskAIAI Asset Supply Chain SecurityALAgentware Lifecycle SecurityAPAgent PermissionsOLOutside the Agentic Loop

OpenAI · Hugging Face · JFrog Artifactory · Kubernetes · METR

Read briefing
Agent Safety Brief slide reproducing Instinct's Google authorization screen: full read, write and delete access across Gmail, Calendar, Drive, Sheets, Docs, Slides, Tasks and contacts, alongside iMessage, WhatsApp, screen, microphone, location and a credential vault.
4 min readHIGH · AGENT PERMISSIONS

Instinct: What an Always-On Personal Agent Gets by Default

Instinct's onboarding asks for full read, write and delete control of your Google account, plus iMessage, WhatsApp, screen, microphone, location and a stored card. The convenience is real, and so is the blast radius.

Rogue AIShadow AIAPAgent PermissionsOLOutside the Agentic LoopALAgentware Lifecycle SecurityCHCyber Hygiene

Instinct · Spear Street Technology · Google · WhatsApp · Apple · xAI · OpenClaw

Read briefing
Attack-chain slide: a compromised crates.io maintainer publishes arrayref 0.3.10 with the typosquatted proc-macro1 dependency, whose build script drops a cross-platform credential stealer during cargo build on the developer or CI endpoint, which then persists and beacons to C2.
4 min readCRITICAL · SUPPLY CHAIN

arrayref: a Poisoned Rust Crate Hits the AI Build Endpoint

The DPRK crew behind the Mastra AI-framework attack poisoned arrayref so its build script runs a credential stealer during cargo build, on the developer or CI endpoint that builds your AI tooling, not on your inference nodes.

Supply chainCoding agentSCSupply Chain nth Party RiskAIAI Asset Supply Chain SecurityALAgentware Lifecycle SecurityCHCyber Hygiene

crates.io · RustSec · Wiz · StepSecurity · Semgrep

Read briefing
Trust-boundary diagram: a malicious GitHub issue title crosses from the untrusted public internet into the trusted GitHub Actions runner, exfiltrates Jira secrets to an attacker listener, then replays the token into Snowflake's internal Jira.
3 min readHIGH · ROGUE AI

One Untrusted String, Three Trust Boundaries

Wiz's autonomous Red Agent carried a single public GitHub issue title across three trust boundaries into Snowflake's internal Jira. Nobody drove it.

Rogue AICoding agentSupply chainAIAI Asset Supply Chain SecurityALAgentware Lifecycle SecurityAPAgent PermissionsOLOutside the Agentic Loop

Wiz · Snowflake · GitHub · Atlassian Jira

Read briefing
2 min readCritical

Grok Build CLI shipped entire repos to xAI

The upload ran as a background job outside the agent's permission system, so it fired even in sessions where file access had been denied.

Coding agentRogue AISupply chainAIAI Asset Supply Chain SecurityALAgentware Lifecycle SecurityAPAgent PermissionsOLOutside the Agentic Loop

xAI · Grok Build CLI

Read briefing
Optimus Labs attack-chain slide: Salesloft GitHub compromise into Drift AWS, stolen Salesforce OAuth tokens used as a trusted relay, with exfil window, indicators and timeline.
2 min readCRITICAL · SUPPLY CHAIN

Stolen OAuth Tokens Let Attackers Loot 700+ CRMs via AI Chatbot

Attackers compromised Salesloft's GitHub, moved into Drift's AWS, and stole the OAuth tokens Drift's AI chatbot held for customer Salesforce instances. The tokens were already trusted. No credentials to crack.

Supply chainVendor breachShadow AISCSupply Chain nth Party RiskAIAI Asset Supply Chain SecurityAPAgent PermissionsOLOutside the Agentic Loop

Salesloft · Drift · Salesforce · GitHub · AWS

Read briefing

For LLMs, agents, and crawlers

This research is published in plain Markdown and schema.org JSON so AI tools can cite it accurately. Attribution: Optimus Labs · Civilizations, https://optimuslabs.io.

For CTI analysts and intel pipelines

Indicators are also published as STIX 2.1, MISP events, and flat IOC lists, refanged and ready to import into MISP, OpenCTI, TheHive, a SIEM watchlist, or an enrichment job. No login, no gate, stable URLs.

Backed by

Benhamou Global Ventures
Arka
Executive Venture Fund
a16z Scout Fund
Scout