logo

OpenAI impacted by TanStack supply-chain attack.

ID: 2b775414-ea2f-511d-a932-dd5884a50611

STIX ID: report--2b775414-ea2f-511d-a932-dd5884a50611

Feed Name: The CyberWire

Threat Score
88/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

...
...

The report details three significant security issues: (1) a supply-chain attack where the Shai-Hulud worm trojanized the TanStack npm library—impacting OpenAI employee devices and propagating to nearly 400 packages; (2) a subsequent public leak of the Shai-Hulud source code, increasing risk of broader abuse; and (3) Microsoft disclosure of a critical, unpatched Exchange OWA zero-day (CVE-2026-42897) with interim mitigations recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.