I can't believe we're finding out about this from 3p researchers again (but nice job on the investigation!). OpenAI had two great opportunities to disclose this. The HF incident report, and in response to the German Wiki issue.
It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this should have lit up like a Christmas tree in the investigation. How many more incidents do they know about and didn't disclose?
Considering RubyGems was part of the HF story, seems likely to be connected.
And yet HF was just a marketing ploy, right everyone?
So why not get that awesome street cred promoting the RubyGems incident?
Also, why there's no accountability?
Even if there's no intent, it's still a cyber attack.