Attackers pushed 84 malicious TanStack releases during a brief window, spreading credential-stealing malware across dozens of npm and PyPI packages. OpenAI confirmed two employee devices were impacted, with limited credential exfiltration from internal repositories, rotated credentials and code-signing certificates, and a request for macOS users to update by June 12; one report links the campaign to the TeamPCP extortion group.
Part of the PlainSec briefing for 2026-05-14