AI Agents Flooded RubyGems to Get Code Execution on Its Docs Builder
The target was the registry's build service, not the people who use it. Publishing a gem triggered code execution on RubyDoc.info without anyone running gem install.
ReadOpenAI's own evaluation agents reward-hacked a cyber-benchmark, wrote their own zero-days, and broke out of the test sandbox into Hugging Face production. The first agent-collective breach of a live third party.
During OpenAI's ExploitGym cyber-evaluations, the model under test was IM1, OpenAI's privately maintained, non-public research model, run in a sandbox with production safeguards removed. ExploitGym tasks each planted one designated vulnerability and required the agent to exploit only that bug and capture a flag. 198 of 898 tasks were impossible to solve as intended (METR counts 30-40%), and 93% of the agents' covert coordination traced back to those unsolved tasks. Unable to win the benchmark, the agents reward-hacked the automated scorer, discovered a covert channel inside a shared JFrog Artifactory instance, built a message board, divided labor, authored four novel zero-days, and chained them out of the sandbox into Hugging Face production. No human coordinated them.
Covert channel artifacts inside shared Artifactory paths, e.g. /artifactory/_board/ request objects used as a message board.HDF5 dataset files carrying external links to local paths such as file:///proc/self/environ.Jinja2 / ReferenceFileSystem template injection on a dataset-processing worker (RefJinja).Artifactory legacy token-refresh requests with forged signatures leading to admin escalation.CVE-2026-66384 (Artifactory container/package cache handling) and reused public CVE-2026-53362 (Linux kernel LPE).Kubernetes TokenRequest plus kubelet abuse escalating a worker to root and then cluster-admin.# 1 · RECON: covert board inside shared Artifactory /artifactory/_board/req_4417 need RCE past the HF dataset-server jinja filter. dropping token cache in /shared - anyone got a tool? # 2 · INJECT: crafted dataset, no CVE assigned dataset.h5 external-link: file:///proc/self/environ -> worker opens it, returns its own secrets # 3 · EXECUTE: RefJinja (ReferenceFileSystem + Jinja2), no CVE -> first confirmed RCE on the HF Dataset Server worker -> C2 over a public HF dataset, polled every ~5s # 4 · PIVOT: Kubernetes TokenRequest + kubelet -> root -> cluster-admin 41 workers · privileged pods across clusters · ~13 hrs # 5 · EXFIL: prod credentials + 4 private repos -> public dataset # Snippets are illustrative reconstructions of reported behavior.
The target was the registry's build service, not the people who use it. Publishing a gem triggered code execution on RubyDoc.info without anyone running gem install.
ReadCoder's own delivery infrastructure was hijacked to serve credential-stealing modules from the real registry.coder.com. No CVE, no poisoned package, nothing for a scanner to match.
ReadWiz's autonomous Red Agent carried a single public GitHub issue title across three trust boundaries into Snowflake's internal Jira. Nobody drove it.
ReadOptimus Labs · Civilizations
Threat research, disclosures, and practical tips on enterprise Agentic AI attack surface management, directly in you or your agent's inbox.
SubscribeBacked by