OpenAI said two employee devices were compromised after a malicious @tanstack/* npm package was installed during the broader Mini Shai-Hulud supply-chain campaign. The intrusion led to theft of a limited amount of internal credential material from repositories accessible to the affected employees, but the company said it found no evidence that customer data, production systems, deployed software, intellectual property, or production code were compromised or altered. OpenAI isolated the affected systems, revoked sessions, rotated credentials, restricted code-deployment workflows, and brought in a third-party incident response firm.
The incident is tied to a wider attack on the npm ecosystem in which attackers allegedly abused TanStack’s GitHub Actions and CI/CD release pipeline to publish 84 malicious versions across 42 @tanstack/* packages, stealing developer and cloud credentials. OpenAI is rotating signing certificates for several desktop products, including macOS apps, and warned users to update before June 12 because older certificates will be blocked from new notarizations. The campaign follows other identity-driven npm compromises, including the trojanized axios releases 1.14.1 and 0.30.4, underscoring how stolen maintainer or publisher credentials can turn trusted software channels into malware delivery paths.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-15, Mistral AI said trojanized npm and PyPI SDK releases stemming from the TanStack supply-chain compromise affected one developer device. The company said it found no evidence that its broader infrastructure was breached.
By 2026-05-15, reporting and security researchers had associated the broader 'Mini Shai-Hulud' npm supply-chain campaign with TeamPCP. The activity was described as targeting npm ecosystems, CI/CD infrastructure, GitHub Actions workflows, and developer and cloud credentials.
On 2026-05-15, OpenAI publicly disclosed that the TanStack supply-chain attack affected two employee devices but said there was no evidence customer data, production systems, deployed software, intellectual property, or production code were compromised. It warned macOS users to update certain OpenAI desktop applications by 2026-06-12, after which Apple protections would block apps signed with the old certificate.
Following the compromise, OpenAI isolated affected systems, revoked sessions, rotated credentials, restricted code deployment workflows, and engaged a third-party incident response firm. Because impacted repositories contained code-signing certificates, the company also began rotating signing certificates and coordinated with platform providers to block new notarizations using the old certificates.
On 2026-05-11, OpenAI said two employee devices were compromised after its corporate environment installed a malicious TanStack npm package during the broader 'Mini Shai-Hulud' supply-chain campaign. The intrusion enabled theft of a limited amount of internal credential material from repositories accessible to the affected employees.
Attackers abused weaknesses in TanStack's GitHub Actions workflows and CI/CD configuration to publish malicious packages through the project's legitimate release pipeline. TanStack later confirmed 84 malicious package versions were published across 42 @tanstack/* packages to steal developer and cloud credentials.
Several other open-source projects were also compromised during March 2026 in related supply-chain activity targeting trusted publisher identities and software delivery channels. The campaign highlighted abuse of maintainer accounts and CI/CD trust relationships rather than exploitation of software flaws.
In March 2026, attackers reportedly hijacked an axios maintainer account and published malicious axios versions 1.14.1 and 0.30.4. The releases pulled in the dependency plain-crypto-js, whose obfuscated postinstall script deployed a cross-platform remote access trojan.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.