OpenAI hit by supply chain attack linked to malicious TanStack packages
ID: 801620b1-6b95-5137-ad20-c071e5e415aa
STIX ID: report--801620b1-6b95-5137-ad20-c071e5e415aa
Feed Name: Security Affairs
OpenAI was impacted by a TanStack-related supply-chain campaign (attributed to TeamPCP) in which the Mini Shai-Hulud worm was distributed through hijacked release pipelines; two employee devices downloaded malicious packages, credentials and code-signing certificates were exfiltrated from internal repositories, and OpenAI mitigated the incident by rotating credentials, revoking certificates, and tightening deployment controls with no evidence of customer or production-system compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
