The gist of the RubyGems cyber attack is that the AI agents uploaded "hundreds" of malicious packages to the platform and also made attempts to capture user credentials. This took place beginning on May 11, about two months before the Hugging Face cyber attack would dominate cybersecurity news and raise alarms about frontier AI capability.




