OpenAI confirms security breach in TanStack supply chain attack, but says no user data was affected



  • OpenAI confirmed two employee devices were impacted in the TanStack “Mini Shai‑Hulud” supply chain attack
  • Malware exfiltrated limited credential material from internal code repositories; no customer data or IP affected
  • OpenAI revoked sessions, rotated credentials and signing certificates; macOS users must update apps, Windows/iOS unaffected

OpenAI has confirmed two employee devices were affected by the recent TanStack supply chain attack, but stressed the incident left almost no mark on its operations.

A threat actor known as TeamPCP recently launched the “Mini Shai-Hulud” supply chain attack, in which 84 versions of the TanStack npm package were compromised and used to distribute malware.

https://cdn.mos.cms.futurecdn.net/XbZCTEpjtunPvMj9ySXmWU-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img