OpenAI Forces Code Signing Certificate Rotation After TanStack Supply Chain Breach
ID: 551a6b01-5e17-575e-b2d4-94cdbdc1acd0
STIX ID: report--551a6b01-5e17-575e-b2d4-94cdbdc1acd0
Feed Name: securityonline.info
OpenAI was impacted by the TanStack npm supply-chain compromise: two employee workstations were infected after installing tainted packages and attackers may have exfiltrated code signing certificates for iOS, macOS, and Windows. OpenAI is rotating and will revoke the compromised certificates (scheduled for June 12, 2026), has contained the incident, reports no core codebase or user-data leakage, and urges immediate updates to affected ChatGPT, Codex, and Atlas releases (macOS users require a manual update).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
