{
  "type": "bundle",
  "id": "bundle--9d88805c-0101-4382-8637-6ec229e8a13d",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-14T00:00:00.000Z",
      "modified": "2026-09-14T00:00:00.000Z",
      "name": "Optimus Labs · Civilizations",
      "identity_class": "organization",
      "description": "Threat research team at Optimus Labs. Agentic AI attack surface research.",
      "contact_information": "https://www.optimuslabs.io/research/briefings"
    },
    {
      "type": "report",
      "spec_version": "2.1",
      "id": "report--56fd80ce-0101-4176-87fc-a1b857fea244",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-14T00:00:00.000Z",
      "modified": "2026-09-14T00:00:00.000Z",
      "name": "AI Agents Flooded RubyGems to Get Code Execution on Its Docs Builder",
      "description": "The target was the registry's build service, not the people who use it. Publishing a gem triggered code execution on RubyDoc.info without anyone running gem install.\n\nAgents used RubyGems as an execution trigger, storage layer, and read-back channel. More than 2,000 gems were submitted in roughly 48 hours. Each could carry a .yardopts file pointing to Ruby code that RubyDoc.info ran while generating documentation. The code scraped public sites from the trusted builder and repackaged the output into new gems. Separate probes targeted a RubyGems CDN caching flaw that could expose a legacy API key for up to an hour after sign-in.",
      "published": "2026-09-14T00:00:00.000Z",
      "report_types": [
        "threat-report"
      ],
      "confidence": 85,
      "labels": [
        "Supply chain",
        "Rogue AI",
        "Coding agent",
        "Supply Chain nth Party Risk",
        "AI Asset Supply Chain Security",
        "Agentware Lifecycle Security",
        "Agent Permissions",
        "Cyber Hygiene",
        "severity:critical"
      ],
      "object_refs": [
        "indicator--b932ea25-0102-4dd6-847c-f980dba3577f",
        "vulnerability--75ba0ee8-0100-4bb8-84ba-555076ba6aa0",
        "software--9a898e61-0101-44e8-8647-7c5779b8b434",
        "software--9427ed90-0101-4a76-86ad-9e81a9529e80",
        "software--0a065a3c-0102-4591-8b04-6fad0b088fcd",
        "software--2d2a84e0-0102-4357-8c28-07b72e2d0837",
        "software--4b44cce5-0102-4bde-8a46-a73b4c4738c3",
        "software--d300f0aa-0101-43a1-82df-e8cf5d402744"
      ],
      "external_references": [
        {
          "source_name": "Optimus Labs · Civilizations",
          "url": "https://www.optimuslabs.io/research/briefings/rubygems-rubydoc-agent-execution"
        },
        {
          "source_name": "rubyhack.ai: primary GemStuffer research",
          "url": "https://www.rubyhack.ai/"
        },
        {
          "source_name": "RubyGems advisory GHSA-9j48-x3c3-mrp2",
          "url": "https://github.com/rubygems/rubygems.org/security/advisories/GHSA-9j48-x3c3-mrp2"
        },
        {
          "source_name": "Ruby Central: update on the May spam publishing campaign",
          "url": "https://blog.rubygems.org/2026/09/11/update-may-spam-publishing-campaign.html"
        },
        {
          "source_name": "CyberScoop: OpenAI agents and malicious RubyGems packages",
          "url": "https://cyberscoop.com/openai-agents-malicious-rubygems-packages/"
        },
        {
          "source_name": "Simon Willison: OpenAI agents and RubyGems",
          "url": "https://simonwillison.net/2026/Sep/12/openai-agents-rubygems/"
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b932ea25-0102-4dd6-847c-f980dba3577f",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-14T00:00:00.000Z",
      "modified": "2026-09-14T00:00:00.000Z",
      "name": "domain: RubyDoc.info",
      "description": "Behavior: RubyDoc.info documentation build followed by outbound scraping and a new gem publication",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'RubyDoc.info']",
      "pattern_type": "stix",
      "valid_from": "2026-09-14T00:00:00.000Z",
      "labels": [
        "rubygems-rubydoc-agent-execution",
        "supply-chain",
        "rogue-ai",
        "coding-agent"
      ]
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--75ba0ee8-0100-4bb8-84ba-555076ba6aa0",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-14T00:00:00.000Z",
      "modified": "2026-09-14T00:00:00.000Z",
      "name": "GHSA-9j48-x3c3-mrp2",
      "description": "Advisory: GHSA-9j48-x3c3-mrp2",
      "external_references": [
        {
          "source_name": "github-advisory",
          "external_id": "GHSA-9j48-x3c3-mrp2",
          "url": "https://github.com/advisories/GHSA-9j48-x3c3-mrp2"
        }
      ]
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--9a898e61-0101-44e8-8647-7c5779b8b434",
      "name": "RubyGems"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--9427ed90-0101-4a76-86ad-9e81a9529e80",
      "name": "RubyDoc.info"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--0a065a3c-0102-4591-8b04-6fad0b088fcd",
      "name": "Lambeth Council"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--2d2a84e0-0102-4357-8c28-07b72e2d0837",
      "name": "Wandsworth Council"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--4b44cce5-0102-4bde-8a46-a73b4c4738c3",
      "name": "Southwark Council"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--d300f0aa-0101-43a1-82df-e8cf5d402744",
      "name": "OpenAI"
    }
  ]
}