Threats & Adversaries · Supply Chain
Malicious Packages Hit Developer Laptops, Not Production The real compromise surface is developer endpoints. A routine package install became a credential theft event on employee laptops, and the standard response of checking production systems misses that the secrets were taken from workstations first.
TanStack says attackers pushed 84 malicious versions in a six-minute window, and a researcher spotted it within 20 minutes. OpenAI has now confirmed two employee devices were impacted, with limited credential material taken from internal repositories they could access, but no evidence of user-data access, production-system compromise, or altered software.
The risk now is reuse. Credentials stolen from developer machines can reach source control, CI/CD, cloud consoles, and signing systems long after the malicious package versions are removed.
6 sources · May 18
Timeline Sources May 18 The Register Security
OpenAI caught in TanStack npm supply chain chaos after employee devices compromised
Attackers stole a limited amount of internal credential material after malware hidden in poisoned packages reached two staff machines
original May 15 The Hacker News
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
Mini Shai-Hulud hit 2 OpenAI devices via TanStack, exposing limited credentials and forcing macOS certificate updates by June 12, 2026.
original May 15 SecurityWeek
OpenAI Hit by TanStack Supply Chain Attack
Two employee devices were compromised in the attack, and credential material was stolen from OpenAI code repositories.
original Part of the PlainSec briefing for 2026-05-14
Every edition of this story: Malicious Packages Hit Developer Laptops, Not Production
More from today
Threats & Adversaries · Supply Chain
Malicious Packages Hit Developer Laptops, Not Production The real compromise surface is developer endpoints. A routine package install became a credential theft event on employee laptops, and the standard response of checking production systems misses that the secrets were taken from workstations first.
TanStack says attackers pushed 84 malicious versions in a six-minute window, and a researcher spotted it within 20 minutes. OpenAI has now confirmed two employee devices were impacted, with limited credential material taken from internal repositories they could access, but no evidence of user-data access, production-system compromise, or altered software.
The risk now is reuse. Credentials stolen from developer machines can reach source control, CI/CD, cloud consoles, and signing systems long after the malicious package versions are removed.
6 sources · May 18
Timeline Sources May 18 The Register Security
OpenAI caught in TanStack npm supply chain chaos after employee devices compromised
Attackers stole a limited amount of internal credential material after malware hidden in poisoned packages reached two staff machines
original May 15 The Hacker News
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
Mini Shai-Hulud hit 2 OpenAI devices via TanStack, exposing limited credentials and forcing macOS certificate updates by June 12, 2026.
original May 15 SecurityWeek
OpenAI Hit by TanStack Supply Chain Attack
Two employee devices were compromised in the attack, and credential material was stolen from OpenAI code repositories.
original Part of the PlainSec briefing for 2026-05-14
Every edition of this story: Malicious Packages Hit Developer Laptops, Not Production
More from today