Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OpenAI Addresses TanStack Supply Chain Breach

OpenAI Addresses TanStack Supply Chain Breach

Posted on May 15, 2026 By CWS

OpenAI has announced its response to the recent TanStack supply chain breach, revealing that some credential information was extracted from its internal source code repositories. This incident is part of a broader attack that occurred earlier this year.

Details of the TanStack Breach

The attack on TanStack, an open-source web application framework, took place on May 11. The attack was orchestrated by the TeamPCP hacking group, which exploited vulnerabilities in the package publishing process. As a result, 84 malicious artifacts were released across 42 packages.

In a coordinated effort, over 170 packages were compromised across several notable NPM and PyPI namespaces. The attack led to the infection of developer devices with the Shai-Hulud worm, impacting organizations like OpenAI.

Impact on OpenAI and Security Measures

Two OpenAI employee devices were infected during this attack, leading to the exfiltration of credentials and other sensitive materials. The attackers gained limited access to certain internal source code repositories. However, OpenAI confirmed that no customer data or proprietary code was affected.

In response, OpenAI has rotated credentials across all affected repositories, revoked user sessions, and temporarily halted code deployment workflows. Additionally, the organization emphasized that no customer data was impacted by this breach.

Future Security Enhancements

The compromised code repositories contained code-signing certificates for various platforms, including iOS, macOS, Windows, and Android. OpenAI has decided to revoke these certificates and re-sign all applications. macOS users must update their applications by June 12, 2026, to continue receiving updates and ensure proper functionality.

OpenAI is also collaborating with platform providers to stop new notarizations and prevent the misuse of stolen certificates. The company has confirmed no unauthorized software signing has occurred and verified that their published software remains uncompromised.

This incident happened during OpenAI’s transition to more secure configurations, prompted by a previous supply chain attack. The phased implementation meant the affected employee devices had not yet received the updated security measures, which could have prevented the malicious downloads.

Related cybersecurity developments highlight the ongoing challenges organizations face in protecting against supply chain vulnerabilities and emphasize the importance of robust security protocols.

Security Week News Tags:Credentials, Cybersecurity, macOS, NPM, OpenAI, PyPI, security certificates, Software Security, supply chain attack, TanStack

Post navigation

Previous Post: OpenAI Faces Supply Chain Cyberattack: macOS Updates Needed
Next Post: Hackers Exploit OrBit Rootkit to Steal Linux Credentials

Related Posts

Siemens Notifies Customers of Microsoft Defender Antivirus Issue Siemens Notifies Customers of Microsoft Defender Antivirus Issue Security Week News
Cybersecurity M&A Roundup: 41 Deals Announced in June 2025 Cybersecurity M&A Roundup: 41 Deals Announced in June 2025 Security Week News
Ray Security Emerges From Stealth With M to Bring Real-Time, AI-Driven Data Protection Ray Security Emerges From Stealth With $11M to Bring Real-Time, AI-Driven Data Protection Security Week News
China’s Salt Typhoon Hackers Target Canadian Telecom Firms China’s Salt Typhoon Hackers Target Canadian Telecom Firms Security Week News
Coyote Banking Trojan First to Abuse Microsoft UIA Coyote Banking Trojan First to Abuse Microsoft UIA Security Week News
Optimizely Suffers Cyberattack Through Vishing Tactics Optimizely Suffers Cyberattack Through Vishing Tactics Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple Warns iPhone Users of Spyware Threats in 110 Countries
  • AmnesiaStealer Malware Targets macOS Through Fake Sites
  • Beacon CRM Data Breach: Full Database Stolen After AWS Key Leak
  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple Warns iPhone Users of Spyware Threats in 110 Countries
  • AmnesiaStealer Malware Targets macOS Through Fake Sites
  • Beacon CRM Data Breach: Full Database Stolen After AWS Key Leak
  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark