OpenAI confirms security breach in TanStack supply chain attack, but says no user data was affected



  • OpenAI confirmed that two employee devices were affected in the TanStack “Mini Shai-Hulud” supply chain attack
  • The malware extracted limited credential material from internal code repositories; no client data or IP is affected
  • OpenAI revoked sessions, rotated credentials, and signed certificates; macOS users must update apps, Windows/iOS is not affected

OpenAI confirmed that two employee devices were affected by the recent attack on TanStack’s supply chain, but emphasized that the incident left almost no trace on its operations.

A threat actor known as TeamPCP recently launched the “Mini Shai-Hulud” supply chain attack, in which 84 versions of the TanStack npm package were compromised and used to distribute malware.

Leave a Comment

Your email address will not be published. Required fields are marked *