OpenAI Confirms Security Breach Via TanStack npm Supply Chain Attack
ID: a15e63c9-d7f9-5dce-bf15-f9443eaf63fd
STIX ID: report--a15e63c9-d7f9-5dce-bf15-f9443eaf63fd
Feed Name: cybersecurityNews.com
A coordinated supply-chain campaign called “Mini Shai-Hulud,” attributed to the TeamPCP extortion gang, injected malicious code into the TanStack npm project (and many other packages), enabling attackers to publish trojanized releases that infected downstream developer systems. OpenAI confirmed two employee workstations were compromised with credential-focused exfiltration from a limited set of internal repositories (including code-signing certificates), but reported no customer data or production systems impacted; OpenAI contained the incident, rotated certificates and credentials, and advised macOS users to update affected apps before Apple blocks binaries signed with the old certificate. The incident highlights the rapid cascading risk in modern open-source supply chains and the targeting of CI/CD, tokens, and developer/cloud credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
