OpenAI says two employees were affected in TanStack supply chain attack

by

OpenAI said two employees’ devices were breached in the recent TanStack supply chain attack that hit hundreds of npm and PyPI packages, prompting the company to rotate code-signing certificates for its apps as a precaution.

KEY FACTS

  • Impact The company said customer data, production systems, intellectual property and deployed software were not affected.
  • Scope The breach was tied to the Mini Shai-Hulud supply-chain campaign targeting trusted software packages.
  • Response OpenAI isolated affected systems, revoked sessions, rotated credentials and restricted deployment workflows.
  • Certificates Code-signing certificates for macOS, Windows, iOS and Android were exposed.
  • Users MacOS users may need to update desktop apps before June 12, 2026.

In a security advisory from OpenAI, the company said it saw unauthorized access and credential-focused exfiltration activity in a limited set of internal source code repositories used by the two employees.

Only limited credentials were taken from those repositories, and the company said there is no evidence they were used in follow-on attacks. OpenAI also said it worked with a third-party incident response firm to investigate the intrusion.

The affected code-signing certificates were not detected being used to sign malicious software, but the company is rotating them anyway. Apple notarization requirements mean older macOS builds may stop launching or receiving updates after the deadline.

The disclosure said the incident fits a broader campaign that began with compromised TanStack and Mistral AI packages before spreading through stolen CI/CD credentials and legitimate release workflows. Researchers at Socket and Aikido tracked hundreds of compromised packages in the campaign.

OpenAI said the case shows how attacks on upstream libraries and package managers can spread quickly across organizations. Windows and iOS users do not need to take any action, the company said.

WHY IT MATTERS

The case highlights how a supply chain breach can reach multiple companies through trusted development tools and workflows. It also shows why vendors are rotating credentials and certificates even when there is no sign of direct customer impact.