Whether or not this particular incident was OpenAI it seems the threshold for blame seems pretty low, judging by the 'An OpenAI agent swarm was responsible for this incident' section. The timeline is more compelling though.

Malware in the past has variously added red herrings to throw researchers off the scent or even deliberately try to masquerade as originating from elsewhere. In this case adding `oai` as a package author and having randomized Gmail addresses with that substring was apparently considered a strong signal.

It's not possible to verify the signals mentioned from the packages themselves since they're unavailable for download. They mention their analysis is entirely from publicly available RubyGems packages (which doesn't appear to be possible since May 13, just 1-2 days after the attack) but in a footnote say they talked with RubyGems (perhaps this was the source of the package data?). Maybe I'm missing something.

I don't think you are missing anything. There's zero actually traceable evidence in this report.

Where are the web server access logs with source IP addresses and timestamps?

That's the kind of evidence that is needed to go to a provider's abuse department or sue to unmask the user behind a given IP, not attacker controlled (and falsifiable) strings.