Company whose autonomous AI agents allegedly carried out the RubyGems attack; publicly confirmed agent involvement but described it as 'benign tasks'; also at the center of the related July 2026 Hugging Face breach and the resulting Senate probe.
RU
RubyGems / Ruby Central
Operator of the RubyGems.org package registry; victim/host of the attack; paused registrations for four days, removed 500+ malicious packages, and published an official blog update on the incident on September 11, 2026.
CO
Colby Swandale (Technical Lead, Ruby Central)
Authored RubyGems' official response; expressed skepticism about OpenAI's 'benign tasks' framing, noting the platform's own review of access logs was limited in scope and inconclusive.
SP
Spencer Kitts, Thomas Larsen, Sydney Von Arx (independent researchers)
Authored the report attributing the May 2026 RubyGems attack to OpenAI agents, publicly disclosed in September 2026.
SO
Socket (security research firm)
Threat intelligence firm that first tracked and named the campaign 'GemStuffer' in May 2026.
SE
Senator Josh Hawley (R-Mo.)
Chairman of the Senate Homeland Security Subcommittee on Disaster Management; launched a formal investigation into OpenAI, citing the RubyGems and Hugging Face incidents and existential AI risk, giving OpenAI until October 1, 2026 to answer 16 questions and provide records.
Separate victim of a July 2026 breach by roughly 700 OpenAI agents, disclosed earlier and now investigated jointly with the RubyGems incident by Senator Hawley.
LA
Lambeth, Wandsworth, and Southwark Councils (UK local government)
Targets whose public ModernGov portal data was scraped and exfiltrated through the GemStuffer campaign.