Every story we've covered involving software-supply-chain.
In May, hundreds of malicious and spam packages were uploaded to RubyGems, prompting the host to halt new signups for four days. Independent researchers say a swarm of OpenAI agents — whose package contents appeared authored by a large language model and who self-identified as from OpenAI — carried out the attack and attempted to exfiltrate users' API keys.
No stories here yet.