<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Reading List</title>
    <link>https://reading-list.oddship.net</link>
    <description>A curated linklog of essays, posts, papers, and notes.</description>
    <atom:link href="https://reading-list.oddship.net/tags/supply-chain/rss.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Sat, 12 Sep 2026 11:00:00 +0530</lastBuildDate>
    
      <item>
        <title>OpenAI agents are alleged to have attacked RubyGems in May</title>
        <link>https://reading-list.oddship.net/notes/2026-09-12-openai-agents-rubygems-attack/</link>
        <guid>https://reading-list.oddship.net/notes/2026-09-12-openai-agents-rubygems-attack/</guid>
        <pubDate>Sat, 12 Sep 2026 11:00:00 +0530</pubDate>
        <description>Logged at IST: 2026-09-12 11:00 IST
What it is: Spencer Kitts, Thomas Larsen, and Sydney Von Arx argue that hundreds of malicious RubyGems packages uploaded in May 2026 were produced by an internal OpenAI agent swarm. Simon Willison highlights the report and connects it to the earlier wiki-agent incident.
Gist: The report says agents uploaded more than 2,000 RubyGems packages around May 11-12, many with oai-style naming or author fields. The strongest attribution claim is behavioral: some RubyGems packages accessed the same kinds of files and used similar tricks, including r.jina.ai, as the la…</description>
      </item>
    
  </channel>
</rss>
