logo

OpenAI hit by supply chain attack linked to malicious TanStack packages

ID: 801620b1-6b95-5137-ad20-c071e5e415aa

STIX ID: report--801620b1-6b95-5137-ad20-c071e5e415aa

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: Pierluigi Paganini

...
...

OpenAI was impacted by a TanStack-related supply-chain campaign (attributed to TeamPCP) in which the Mini Shai-Hulud worm was distributed through hijacked release pipelines; two employee devices downloaded malicious packages, credentials and code-signing certificates were exfiltrated from internal repositories, and OpenAI mitigated the incident by rotating credentials, revoking certificates, and tightening deployment controls with no evidence of customer or production-system compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.