This item was held from publication because the primary source URL was inaccessible and the available metadata — a headline and a Hacker News thread reference — does not provide enough verified detail to report accurately.

Publishing specifics about a security incident (attack vectors, scope, responsible parties, disclosure timeline) without confirmed facts risks misleading readers and potentially mischaracterizing the actions of the organizations involved.
We will revisit this story once the rubyhack.ai writeup is accessible or official statements from OpenAI and the RubyGems maintainers are available. If you have primary source material, please share it with the editorial team.
