OpenAI confirms security breach in TanStack supply chain attack, but says no user data was affected


  • OpenAI confirmed that two employees’ devices were affected in the TanStack “Mini Shai-Hulud” supply chain attack
  • Malware exfiltrated limited credential material from internal code repositories; no customer data or IP affected
  • OpenAI revoked sessions, rotated credentials and signing certificates; macOS users must update apps, Windows/iOS are unaffected

OpenAI has confirmed that two employee units were affected by the recent TanStack supply chain attack, but emphasized that the incident had little to no impact on operations.

A threat actor known as TeamPCP recently launched the “Mini Shai-Hulud” supply chain attack where 84 versions of the TanStack npm package were compromised and used to distribute malware.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top