Threats · 119 days ago
The real compromise surface is developer endpoints. A routine package install became a credential theft event on employee laptops, and the standard response of checking production systems misses that the secrets were taken from workstations first.
TanStack says attackers pushed 84 malicious versions in a six-minute window, and a researcher spotted it within 20 minutes. OpenAI has now confirmed two employee devices were impacted, with limited credential material taken from internal repositories they could access, but no evidence of user-data access, production-system compromise, or altered software.
The risk now is reuse. Credentials stolen from developer machines can reach source control, CI/CD, cloud consoles, and signing systems long after the malicious package versions are removed.
6 sources covering this story
OpenAI caught in TanStack npm supply chain chaos after employee devices compromised
Attackers stole a limited amount of internal credential material after malware hidden in poisoned packages reached two staff machines
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
Mini Shai-Hulud hit 2 OpenAI devices via TanStack, exposing limited credentials and forcing macOS certificate updates by June 12, 2026.
OpenAI Hit by TanStack Supply Chain Attack
Two employee devices were compromised in the attack, and credential material was stolen from OpenAI code repositories.
The Record from Recorded Future
OpenAI asks macOS users to update after TanStack npm supply chain attack
The actions are being taken in light of an expanding supply chain campaign impacting the popular open-source library TanStack and additional npm and PyPI packages tied to several AI companies.
OpenAI says hackers stole some data after latest code security issue | TechCrunch
OpenAI said the damage was limited to the employees’ devices and did not affect user data nor its production systems, and none of its intellectual property was stolen.
OpenAI confirms security breach in TanStack supply chain attack
OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution.
Part of the PlainSec briefing for 2026-05-14