logo

OpenAI Confirms Limited Impact From TanStack npm Supply Chain Attack, Urges macOS App Updates

ID: 1a4ae6db-5184-5281-b6c5-a277bb60704e

STIX ID: report--1a4ae6db-5184-5281-b6c5-a277bb60704e

Feed Name: The Cyber Express

Threat Score
65/100

Date Published: 2026-05-15

Date Updated: 2026-07-20

Author: Samiksha Jain

...
...

OpenAI disclosed that a supply-chain compromise of a TanStack npm package, associated with the Mini Shai-Hulud malware campaign, impacted two employee devices resulting in limited credential theft and access to a small number of internal repositories; no customer data or production systems were reported compromised. The company engaged forensics responders, rotated and will revoke affected code-signing certificates (requiring macOS users to update apps by June 12, 2026), and implemented remediation steps including credential rotation and tighter package/CI controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.