logo

OpenAI confirms security breach in TanStack supply chain attack

ID: 4be5ca57-a9c1-552c-bec5-e7d914bb5e92

STIX ID: report--4be5ca57-a9c1-552c-bec5-e7d914bb5e92

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Lawrence Abrams

...
...

OpenAI disclosed that two employee devices were breached as part of the Mini Shai-Hulud supply-chain campaign linked to the TeamPCP extortion gang, which trojanized hundreds of npm and PyPI packages to steal developer and cloud credentials; OpenAI said customer data and production systems were not impacted but rotated code-signing certificates and performed containment and forensic response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.