Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OpenAI Addresses TanStack Supply Chain Breach

OpenAI Addresses TanStack Supply Chain Breach

Posted on May 15, 2026 By CWS

OpenAI has announced its response to the recent TanStack supply chain breach, revealing that some credential information was extracted from its internal source code repositories. This incident is part of a broader attack that occurred earlier this year.

Details of the TanStack Breach

The attack on TanStack, an open-source web application framework, took place on May 11. The attack was orchestrated by the TeamPCP hacking group, which exploited vulnerabilities in the package publishing process. As a result, 84 malicious artifacts were released across 42 packages.

In a coordinated effort, over 170 packages were compromised across several notable NPM and PyPI namespaces. The attack led to the infection of developer devices with the Shai-Hulud worm, impacting organizations like OpenAI.

Impact on OpenAI and Security Measures

Two OpenAI employee devices were infected during this attack, leading to the exfiltration of credentials and other sensitive materials. The attackers gained limited access to certain internal source code repositories. However, OpenAI confirmed that no customer data or proprietary code was affected.

In response, OpenAI has rotated credentials across all affected repositories, revoked user sessions, and temporarily halted code deployment workflows. Additionally, the organization emphasized that no customer data was impacted by this breach.

Future Security Enhancements

The compromised code repositories contained code-signing certificates for various platforms, including iOS, macOS, Windows, and Android. OpenAI has decided to revoke these certificates and re-sign all applications. macOS users must update their applications by June 12, 2026, to continue receiving updates and ensure proper functionality.

OpenAI is also collaborating with platform providers to stop new notarizations and prevent the misuse of stolen certificates. The company has confirmed no unauthorized software signing has occurred and verified that their published software remains uncompromised.

This incident happened during OpenAI’s transition to more secure configurations, prompted by a previous supply chain attack. The phased implementation meant the affected employee devices had not yet received the updated security measures, which could have prevented the malicious downloads.

Related cybersecurity developments highlight the ongoing challenges organizations face in protecting against supply chain vulnerabilities and emphasize the importance of robust security protocols.

Security Week News Tags:Credentials, Cybersecurity, macOS, NPM, OpenAI, PyPI, security certificates, Software Security, supply chain attack, TanStack

Post navigation

Previous Post: OpenAI Faces Supply Chain Cyberattack: macOS Updates Needed
Next Post: Hackers Exploit OrBit Rootkit to Steal Linux Credentials

Related Posts

Fraudulent Apps Exploit Google Play’s Early Access Program Fraudulent Apps Exploit Google Play’s Early Access Program Security Week News
Free Wi-Fi Leaves Buses Vulnerable to Remote Hacking Free Wi-Fi Leaves Buses Vulnerable to Remote Hacking Security Week News
New HTTP Request Smuggling Attacks Impacted CDNs, Major Orgs, Millions of Websites New HTTP Request Smuggling Attacks Impacted CDNs, Major Orgs, Millions of Websites Security Week News
Cato Networks Raises 9 Million to Expand SASE Business Cato Networks Raises $359 Million to Expand SASE Business Security Week News
Google Finds Data Theft Malware Used by Russian APT in Select Cases Google Finds Data Theft Malware Used by Russian APT in Select Cases Security Week News
US Indicts Russians for Cybercrime Operations US Indicts Russians for Cybercrime Operations Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Citrix Releases Patches for Critical NetScaler Zero-Day Flaws
  • Top Platforms for Effective Enterprise Threat Intelligence
  • Wireshark 4.6.9: Security Enhancements Address 19 Flaws
  • New Windows Attack Bypasses EDR with Process Injection
  • Citrix Urges Immediate Update for NetScaler Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Citrix Releases Patches for Critical NetScaler Zero-Day Flaws
  • Top Platforms for Effective Enterprise Threat Intelligence
  • Wireshark 4.6.9: Security Enhancements Address 19 Flaws
  • New Windows Attack Bypasses EDR with Process Injection
  • Citrix Urges Immediate Update for NetScaler Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark