Safety

OpenAI reports limited credential theft after TanStack supply-chain attack affected employee devices

OpenAI confirmed that two employee devices were impacted by a supply-chain attack that compromised the TanStack open-source library, which pushed 84 infected releases in six minutes.

OpenAI reports limited credential theft after TanStack supply-chain attack affected employee devices

A supply-chain cyberattack earlier this week targeted dozens of companies’ open-source projects, with attackers hijacking repositories to publish malicious updates. On Wednesday, OpenAI confirmed that the incident may have affected the devices of two of its employees.

According to TanStack’s disclosures, the attackers published 84 infected releases of the library within six minutes. TanStack detected the intrusion within 20 minutes. The compromised packages contained malware designed to steal credentials from infected machines and to propagate to other systems.

OpenAI stated it detected unauthorized access and that certain authentication credentials were stolen, but characterized the amount of data taken as “limited.” The company said its investigation so far has found no evidence that user data were compromised or that the incident caused other service-impacting problems.

As a precaution, OpenAI rotated multiple certificates, which requires an update to the ChatGPT macOS application. The company did not specify exactly which credentials were stolen, and the identity of the actor or group behind the attack remains unknown.

Reports cited by TechCrunch and TanStack’s own communications highlight how supply-chain attacks on widely used open-source components can enable rapid distribution of malicious code, and underscore the importance of fast detection and certificate rotation as incident-response measures.

Key facts

  • Attackers published 84 infected releases in six minutes.
  • TanStack detected the compromise within 20 minutes.
  • OpenAI says a limited number of authentication credentials were stolen.
  • Several certificates at OpenAI were rotated; the ChatGPT macOS app requires an update.
  • The attacker or group behind the operation has not been identified.

The episode reiterates the systemic risk posed by attacks on open-source supply chains and the need for vigilance in development ecosystems and downstream organizations that consume these components.