OpenAI confirms security flaw in TanStack supply chain attack, but says no user data was affected


  • OpenAI confirmed that two employees’ devices were affected by TanStack ‘Mini Shai‑Hulud’ supply chain attack
  • Malware exfiltrated a limited number of identifying documents from internal code repositories; no customer data or IP assigned
  • OpenAI revoked sessions, credential rotation, and certificate signing; macOS users need to update apps, Windows/iOS are not affected

OpenAI confirmed that two employees’ devices were affected by the recent TanStack supply chain attack, but stressed that the incident left virtually no mark on its operations.

A threat actor known as TeamPCP recently launched the “Mini Shai-Hulud” supply chain attack, in which 84 versions of the TanStack npm package were compromised and used to distribute malware.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top