HomeSecurityOpenAI confirms breach via TanStack supply chain attack

OpenAI confirms breach via TanStack supply chain attack

OpenAI has revealed that two of its employees were affected by the major TanStack supply chain cyberattack linked to the Mini Shai-Hulud, a case that has already caused turmoil in the open-source software world. The attack, which affected hundreds of npm and PyPI packages, led the company to proactively replace code-signing certificates for applications on macOS, Windows, iOS, and Android.

OpenAI TanStack

According to an official statement from the company, there is no indication that customer data, production systems, or critical intellectual property. However, the case highlights once again how vulnerable the modern software development ecosystem can be to attacks that exploit weaknesses in code development and distribution processes.

How the breach occurred

OpenAI linked the incident to the activity of the TeamPCP, which is allegedly behind the Mini Shai-Hulud. The perpetrators targeted popular and trusted software packages, funneling malicious updates through legitimate distribution channels.

See also: FlowerStorm phishing gang adopts virtual machine obfuscation

The company said it detected unauthorized access to a limited number of internal source code repositories used by the two affected employees. The attackers appear to have focused primarily on extracting credentials and access tokens, with no evidence of further exploitation so far.

Although the scope of the breach is described as limited, OpenAI immediately quarantined systems, revoked active login sessions, and replaced credentials in all affected repositories. At the same time, some software development flows were temporarily restricted until security audits.

OpenAI confirms breach via TanStack supply chain attack

Certificate change and warning for macOS users

One of the most significant issues that emerged from the incident concerns the exposure of code-signing certificates used by OpenAI products. Although the company claims that they were not found to be used to distribute malware, it decided to replace them as a precaution.

This process primarily affects macOS, who will need to update their OpenAI desktop applications before June 12, 2026.After this date, applications carrying the old certificates may not launch or receive new updates due to Apple's notarization mechanisms.

On the contrary, Windows and iOS users do not need to take any action, as the company assures that these platforms are not functionally affected by the certificate change.

See also: Ghostwriter targets Ukrainian government with Geofenced PDF Phishing and Cobalt Strike

The attack on TanStack and the chain spread

The OpenAI case is just one part of a broader attack on the software supply chain that began with TanStack and quickly spread to dozens of open source projects.

The attackers exploited vulnerabilities in GitHub Actions streams and CI/CD infrastructures, gaining access to authentication tokens and package publishing mechanisms. In this way, they were able to distribute trojanized versions of packages through perfectly legitimate update channels, which made the attack significantly more difficult to detect.

Security researchers from Socket and Aikido discovered hundreds of compromised packages on npm and PyPI, with organizations affected including Mistral AI, UiPath, Guardrails AI, and OpenSearch.

The Mini Shai-Hulud malware was designed to steal critical development and cloud infrastructure credentials, such as GitHub tokens, npm publishing tokens, AWS credentials, Kubernetes secrets, SSH keys, and .env files. Additionally, researchers found that the malware could persist on developers’ systems through modifications to Claude Code hooks and VS Code autorun tasks

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

OpenAI confirms breach via TanStack supply chain attack

The new reality in cyberattacks

The case confirms a broader trend in cybersecurity: attackers are no longer exclusively targeting large companies, but are seeking to infect the entire software supply chain.

See also: Spyware researcher uncovers “Signal phishing campaign”

With thousands of organizations relying on open source libraries every day, a single compromised package can cause ripple effects on a global scale. Reliance on automated development pipelines, continuous integration tools, and cloud infrastructures significantly increases the attack surface.

Experts estimate that similar attacks will continue to increase in the coming years, forcing technology companies to invest more in zero-trust architectures, software dependency tracking, and stricter code review processes.

The OpenAI case serves as yet another wake-up call for the entire technology industry, reminding us that software security depends not only on protecting end systems, but also on every link in the development chain.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS