OpenAI Hit by TanStack Supply Chain Attack
Want more insights like this?
OpenAI disclosed that two employee devices in its corporate environment were infected during the May 11 TanStack supply chain attack, attributed by researchers to TeamPCP. The attackers exploited weaknesses in package publishing to release 84 malicious artifacts across 42 packages, carrying Mini Shai-Hulud — a variant of the Shai-Hulud worm.
Limited credential material was exfiltrated from a subset of internal source code repositories. OpenAI says it has found no evidence that user data, production systems or intellectual property were affected. It rotated all credentials across the impacted repositories and revoked user sessions.
Those repositories also held code-signing certificates for OpenAI's iOS, macOS and Windows products, which have now been rotated and the apps re-signed. Only macOS users need to act: update ChatGPT Desktop, the Codex app, Codex CLI and Atlas by June 12, 2026, or macOS will start blocking the older builds.
The 84 poisoned versions shipped with valid SLSA Build Level 3 provenance, so signed attestations were no defence. For OpenAI the timing was awkward — it was still hardening after a malicious Axios package reached it through a GitHub Actions workflow in late March.
Source: Security Week