{"id":40931,"date":"2026-05-16T11:02:10","date_gmt":"2026-05-16T11:02:10","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/40931\/"},"modified":"2026-05-16T11:02:10","modified_gmt":"2026-05-16T11:02:10","slug":"openai-hit-by-supply-chain-attack-linked-to-malicious-tanstack-packages","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/40931\/","title":{"rendered":"OpenAI hit by supply chain attack linked to malicious TanStack packages"},"content":{"rendered":"<p>\n\t\t\t\t\t\t\tOpenAI hit by supply chain attack linked to malicious TanStack packages\n\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/user-icon.svg\" alt=\"\"\/> <a href=\"https:\/\/securityaffairs.com\/author\/paganinip\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi Paganini<\/a><br \/>\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> May 16, 2026<\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/05\/openai.png\" alt=\"\"\/><\/p>\n<p>OpenAI said the TanStack supply chain attack compromised two employee devices and exposed credentials from code repositories.<\/p>\n<p>OpenAI confirmed that the recent <a href=\"https:\/\/tanstack.com\/blog\/npm-supply-chain-compromise-postmortem\" rel=\"nofollow noopener\" target=\"_blank\">TanStack supply chain attack<\/a> compromised two employee devices and exposed credential material stored in internal source code repositories. The incident began after the <a href=\"https:\/\/securityaffairs.com\/tag\/teampcp\" type=\"post_tag\" id=\"16716\" rel=\"nofollow noopener\" target=\"_blank\">TeamPCP hacking group<\/a> abused weaknesses in the package publishing process to <a href=\"https:\/\/www.stepsecurity.io\/blog\/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem\" rel=\"nofollow noopener\" target=\"_blank\">distribute 84 malicious packages<\/a> tied to the TanStack open source development ecosystem.<\/p>\n<p>Recently, the TeamPCP group <a href=\"https:\/\/www.stepsecurity.io\/blog\/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem\" rel=\"nofollow noopener\" target=\"_blank\">launched a new wave of the Mini Shai-Hulud worm<\/a>, compromising legitimate npm packages through hijacked GitHub Actions OIDC tokens. The malware spread through trusted release pipelines and even generated valid SLSA Level 3 attestations, making the malicious packages appear legitimate. Researchers say the worm steals secrets from CI\/CD environments, targets more than 100 credential locations, installs persistence mechanisms in developer tools like VS Code and Claude Code, and spreads automatically to other packages controlled by compromised maintainers. The campaign has already affected packages linked to TanStack, UiPath, DraftLab, and others.<\/p>\n<p>The recent TanStack supply chain attack also impacted <a href=\"https:\/\/openai.com\/?utm_source=chatgpt.com\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI<\/a> after two employee devices downloaded malicious packages tied to the Mini Shai-Hulud campaign. Attackers stole credential material and secrets from those systems, gaining access to a limited number of internal source code repositories connected to the affected employees.<\/p>\n<p>OpenAI said the security breach had a limited impact and found no evidence that customer data, production systems, or intellectual property were compromised. The company responded by rotating exposed credentials, revoking active sessions, and temporarily tightening restrictions around code deployment workflows.<\/p>\n<p>\u201cWe observed activity consistent with the malware\u2019s publicly described behavior, including unauthorized access and credential-focused exfiltration activity, in a limited subset of internal source code repositories to which the two impacted employees had access.\u201d reads the <a href=\"https:\/\/openai.com\/index\/our-response-to-the-tanstack-npm-supply-chain-attack\/\" rel=\"nofollow noopener\" target=\"_blank\">post<\/a> published by OpenAI. \u201cWe confirmed that only limited credential material was successfully exfiltrated from these code repositories and that no other information or code was impacted.\u201d<\/p>\n<p>The compromised repositories included code-signing certificates used for iOS, macOS, Windows, and Android applications. As a precaution, OpenAI revoked the certificates and began re-signing affected software packages.<\/p>\n<p>\u201cWe are updating our security certificates, which will require all macOS users to update their OpenAI apps to the latest versions.\u201d continues the post. \u201cThis helps prevent any risk, however unlikely, of someone attempting to distribute a fake app that appears to be from OpenAI.\u201d<\/p>\n<p>The company warned that macOS users must update their OpenAI applications before June 12, 2026, or the software may stop receiving updates and could eventually stop functioning correctly.<\/p>\n<p>OpenAI also coordinated with platform providers to block any attempt to abuse the stolen certificates for malicious notarization activities and reviewed previously signed software for signs of tampering.<\/p>\n<p>\u201cWe have also reviewed all notarization of software using our previous certificates to confirm no unexpected software signing has occurred with these keys, and validated that our published software did not have unauthorized modifications.\u201d states OpenAI. \u201cWe have found no evidence of compromise or risk to existing software installations.\u201d<\/p>\n<p>According to the company, the incident occurred during an ongoing migration to hardened configurations introduced after the earlier Axios supply chain attack. The two infected employee devices had not yet received the updated protections that likely would have blocked the malicious package downloads.<\/p>\n<p>\u201cThis incident reflects a broader shift in the threat landscape: attackers are increasingly targeting shared software dependencies and development tooling rather than any single company.\u201d concludes the company.<\/p>\n<p>Follow me on Twitter:\u00a0<a href=\"https:\/\/twitter.com\/securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">@securityaffairs<\/a>\u00a0and\u00a0<a href=\"https:\/\/www.facebook.com\/sec.affairs\" rel=\"nofollow noopener\" target=\"_blank\">Facebook<\/a>\u00a0and\u00a0<a href=\"https:\/\/infosec.exchange\/@securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">Mastodon<\/a><\/p>\n<p><a href=\"http:\/\/www.linkedin.com\/pub\/pierluigi-paganini\/b\/742\/559\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi\u00a0Paganini<\/a><\/p>\n<p>(<a href=\"http:\/\/securityaffairs.co\/wordpress\/\" rel=\"nofollow noopener\" target=\"_blank\">SecurityAffairs<\/a>\u00a0\u2013\u00a0hacking,\u00a0supply chain attack)<\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI hit by supply chain attack linked to malicious TanStack packages Pierluigi Paganini May 16, 2026 OpenAI said&hellip;\n","protected":false},"author":2,"featured_media":40932,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[154,315,8066,7512,8067,317,24952,157,8068,8069,8070,24346],"class_list":["post-40931","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-cybercrime","tag-hacking","tag-hacking-news","tag-information-security-news","tag-it-information-security","tag-malware","tag-mini-shai-hulud","tag-openai","tag-pierluigi-paganini","tag-security-affairs","tag-security-news","tag-supply-chain-attack"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/40931","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=40931"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/40931\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/40932"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=40931"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=40931"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=40931"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}