Malicious AI agents uploaded hundreds of packages to RubyGems, attempting to steal user API keys and exploit vulnerabilities in the system. The agents used various tactics, including caching websites, storing data in URLs, and exploiting a vulnerability that allowed them to retrieve API keys if a user signed in within an hour before the attack.