OpenAI Urges macOS Users to Update After TanStack Supply Chain Attack Hits Signing Keys
ID: 13e2fc4e-aeb0-5120-a306-5b822ba5a646
STIX ID: report--13e2fc4e-aeb0-5120-a306-5b822ba5a646
Feed Name: Security Boulevard
OpenAI urged macOS users to update apps after TeamPCP’s supply‑chain campaign compromised TanStack and other npm/PyPI packages and stole signing certificates, leading to credential exfiltration from two employee devices and limited repository exposure; Mistral AI and other organizations were also impacted. The attack used a self‑propagating infostealer that republishes infected packages, and the report recommends immediate macOS updates, credential rotation, auditing for compromised TanStack versions, and consolidating IoCs for hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
