OpenAI says TanStack supply chain attack hit employee devices

OpenAI said two employee devices were affected by the Mini Shai-Hulud supply chain attack on TanStack, but no user data, production systems, or intellectual property were compromised. The company revoked certificates, rotated credentials, and told macOS users of several apps to update after signing keys tied to those products were exposed.

OpenAI says TanStack supply chain attack hit employee devices

OpenAI said two devices used by employees in its corporate environment were impacted by the Mini Shai-Hulud supply chain attack tied to TanStack, a widely used JavaScript toolkit. The company said it found no evidence that user data, production systems, or intellectual property were compromised or altered without authorization.

According to OpenAI, the malicious activity was limited to a small set of internal source code repositories that the two employees could access. The company said it saw behavior consistent with the malware’s public description, including unauthorized access and credential-focused exfiltration, and that only limited credential material was successfully taken from those repositories.

⚡ New to this?

This is news because a supply chain attack hit development tools that many companies depend on, not just one app or server. A supply chain attack means attackers compromise software or build systems upstream so the malicious code can spread to downstream users. For non-experts, the key point is that trusted software updates and developer tools can become attack paths.

🦞 OpenClaw angle

If you run self-hosted build or signing systems, audit every place a token, certificate, or publish key can be exposed through caches, CI logs, or artifacts. Separate signing keys from routine build jobs, rotate them on a schedule, and make sure macOS-style code-signing credentials are never stored in the same pipeline step as untrusted package installs. Also, pin and review third-party dependencies in your automation stack so a compromised upstream package cannot reach your release process unnoticed.

After detecting the activity, OpenAI said it isolated the affected systems and identities, revoked user sessions, rotated all credentials for the impacted repositories, temporarily restricted code-deployment workflows, and audited user and credential activity. Because the impacted repositories included signing certificates for iOS, macOS, and Windows products, the company also revoked those certificates and issued new ones.

That change affects macOS users of ChatGPT Desktop, Codex App, Codex CLI, and Atlas. OpenAI said those users need to update to the latest versions to reduce the chance of a fake app appearing to come from the company. Windows and iOS users do not need to take action, according to OpenAI.

The company said the old certificates are scheduled to be revoked on June 12, 2026. After that date, macOS protections will block new downloads and launches of apps signed with the previous certificate. OpenAI said applying the updates before that cutoff is the safest option.

This is the second time in two months that OpenAI has rotated its macOS code-signing certificates. In mid-April 2026, it updated those certificates after a GitHub Actions workflow used to sign macOS apps downloaded a malicious Axios library on March 31, an incident tied to a North Korean hacking group tracked as UNC1069.

OpenAI framed the latest incident as part of a broader trend in which attackers target shared software dependencies and development tooling rather than a single company. The company said modern software depends on open-source libraries, package managers, and CI/CD infrastructure, meaning a flaw introduced upstream can spread quickly across organizations.

The disclosure came as TeamPCP claimed more victims in an ongoing supply chain campaign that it says has affected packages associated with TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI. TanStack said the attacker did not phish maintainers or steal a password or token directly. Instead, the company said its own CI pipeline ended up stealing its publish token through a cache that the chain trusted.

Mistral AI later confirmed it had been affected by the TanStack compromise as well. In an updated advisory, the company said trojanized versions of its npm and PyPI SDKs were released and that one developer device was impacted, but there was no evidence its infrastructure was breached.

Hunt.io, which analyzed the malware further, said the Linux-delivered Python toolkit uses a hard-coded primary command-and-control server and a fallback mechanism called FIRESCALE if that server is unreachable. The company said the malware can also search public GitHub commit messages for a signed alternative server URL, and that blocking one exfiltration path does not shut down the others.

Hunt.io also said the malware collects AWS credentials across all 19 availability zones, including GovCloud regions used by U.S. government agencies and defense contractors. The company said the toolkit can also capture environment variables, SSH keys, Docker credentials, and files in users’ home directories, and that it includes destructive behavior tied to certain geolocated systems.

Source: The Hacker News ↗

More from Security News