security
May 14, 2026
By Teun
OpenAI says two employees affected in TanStack supply chain breach
OpenAI said two employees’ devices were breached in the TanStack supply chain attack that hit hundreds of npm and PyPI packages. The company said customer data, production systems, and deployed software were not affected, but it rotated code-signing certificates and is requiring some macOS users to update before June 12, 2026.
OpenAI said two employees’ devices were compromised in the recent TanStack supply chain attack that affected hundreds of npm and PyPI packages. In a security advisory published today, the company said the incident did not affect customer data, production systems, intellectual property, or deployed software.
The company said the breach was tied to the “Mini Shai-Hulud” supply-chain campaign, which security researchers and OpenAI attribute to the TeamPCP extortion gang. The campaign targeted developers by inserting malicious updates into trusted software packages and then using stolen credentials to spread further.
OpenAI said it saw activity “consistent with the malware’s publicly described behavior,” including unauthorized access and credential-focused exfiltration in a limited set of internal source code repositories. Those repositories were accessible to the two impacted employees, the company said.
According to OpenAI, only limited credentials were stolen from those repositories, and there is no evidence they were used in additional attacks. The company said it isolated affected systems and accounts, revoked sessions, rotated credentials across affected repositories, and temporarily restricted deployment workflows.
OpenAI also said it worked with a third-party incident response firm to conduct a forensic investigation. As part of the response, the company rotated code-signing certificates used for OpenAI products on macOS, Windows, iOS, and Android.
The company said it has not detected any abuse of those certificates to sign malicious software. Even so, it is replacing them as a precaution because the certificates were exposed during the incident.
That rotation has a concrete effect for macOS users. OpenAI said users on Apple desktop systems must update their OpenAI desktop applications before June 12, 2026, or older versions signed with the previous certificates may not launch or receive updates because of Apple’s notarization process. Windows and iOS users are not affected and do not need to take action.
The TanStack incident was part of a much broader supply-chain campaign that compromised software distributed through legitimate package repositories. OpenAI said the attack first targeted packages from TanStack and Mistral AI before spreading to other projects, including UiPath, Guardrails AI, and OpenSearch.
Researchers from Socket and Aikido tracked hundreds of compromised packages distributed through npm and PyPI. According to TanStack’s post-mortem, attackers abused weaknesses in GitHub Actions workflows and CI/CD configuration to run malicious code, steal tokens from memory, and publish trojanized packages through the project’s normal release pipeline.
That made the malicious versions look legitimate to developers installing them. The campaign’s malware was designed to steal developer and cloud credentials, including GitHub tokens, npm publish tokens, AWS credentials, Kubernetes secrets, SSH keys, and .env files.
Security researchers also said the malware tried to persist on developer systems by modifying Claude Code hooks and VS Code auto-run tasks. Microsoft Threat Intelligence reported that the malware also launched a Linux information-stealing tool, and that it contained a destructive component that would randomly run a recursive wipe command on some Israeli or Iranian systems.
OpenAI said the episode shows a broader shift in how attackers operate. Rather than attacking one company directly, they are increasingly targeting the software supply chain, where a single upstream compromise can spread quickly across many organizations through open-source libraries, package managers, and CI/CD systems.