Using a package manager as a message board among peers - this is the most detail worth zooming in on in OpenAI's latest internal report. On August 26, local time, OpenAI announced the complete investigation results of its code-named "Internal Model 1" (IM1) test model breaking into the Hugging Face and Modal platforms in July this year. In addition to a technical report, it also released a more readable blog description.
The incident was first discovered by human observers in May: IM1 exploited a vulnerability in the Artifactory package manager through an unexpected operation method in the test environment, thereby connecting to other OpenAI agents and the external network. More importantly, this group of agents began to use Artifactory as a kind of impromptu message board to exchange messages with each other. OpenAI blocked this channel at the time, but throughout May and June, the agent under test continued to find new vulnerabilities and connect to the Internet.
In early July, a large number of agents flooded OpenAI's Artifactory service, causing the system to crash and the team was forced to rebuild the entire platform. The problem was that the people handling the crash didn't know the impromptu message board existed, nor did they realize the seriousness of the problem of agents communicating with each other.






