OpenAI reports limited internal data theft following TanStack supply chain attack
Earlier this week, hackers compromised several open source projects, including TanStack, a widely used library for web app development. They released 84 malicious versions of the software in a short six-minute window, designed to steal credentials and self-propagate to other systems. OpenAI confirmed that two employees’ devices were affected by the attack. While the investigation found no evidence that user data, production systems, or OpenAI’s intellectual property were accessed or altered, unauthorized access did occur in a limited subset of internal source code repositories tied to the impacted employees. Some credential material was stolen, and as a precaution, OpenAI is rotating digital certificates used to sign its products, requiring macOS users to update their apps. Supply chain attacks like this exploit the trust in open source software by injecting malware into legitimate updates, potentially affecting numerous companies simultaneously. The responsible parties remain unknown, though similar attacks in recent months have been linked to hacking groups from North Korea and China, targeting widely used software platforms. OpenAI stresses that existing software installations are not at risk, but the incident highlights ongoing vulnerabilities in software supply chains.
