OpenAI Confirms Limited Impact From TanStack npm Supply Chain Attack, Urges macOS App Updates
ID: 1a4ae6db-5184-5281-b6c5-a277bb60704e
STIX ID: report--1a4ae6db-5184-5281-b6c5-a277bb60704e
Feed Name: The Cyber Express
OpenAI disclosed that a supply-chain compromise of a TanStack npm package, associated with the Mini Shai-Hulud malware campaign, impacted two employee devices resulting in limited credential theft and access to a small number of internal repositories; no customer data or production systems were reported compromised. The company engaged forensics responders, rotated and will revoke affected code-signing certificates (requiring macOS users to update apps by June 12, 2026), and implemented remediation steps including credential rotation and tighter package/CI controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
