Attackers abused trusted open-source distribution channels to publish malicious package updates, including 84 tainted TanStack releases uploaded within six minutes and a malicious payload discovered in the Guardrails-AI package on PyPI. The compromised packages were built to steal credentials from infected developer devices and move laterally to connected systems, highlighting how software supply-chain attacks can rapidly spread through widely used development dependencies.
OpenAI confirmed that employee devices were affected by the TanStack incident, giving attackers limited access to a small number of internal code repositories. The company said there was no evidence that customer data, production systems, intellectual property, or software releases were compromised, and it reported no persistent threat in operational infrastructure. Researchers detected the malicious activity in about 20 minutes, likely constraining the blast radius, while OpenAI rotated cryptographic certificates associated with the affected repositories as part of containment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Following the repository exposure, OpenAI rotated cryptographic certificates associated with the affected internal code repositories. This was part of its response to contain any potential downstream risk from the compromise.
OpenAI said compromised employee devices in the TanStack supply-chain incident gave attackers limited access to a small number of internal code repositories. The company stated that no customer data, production systems, intellectual property, or software releases were compromised, and it found no evidence of altered production software or persistent threats.
Researchers detected the malicious TanStack package activity within about twenty minutes of the uploads. This rapid identification likely limited the broader impact of the supply-chain attack.
In a six-minute window, attackers uploaded 84 malicious software updates tied to the TanStack supply-chain compromise. The packages were designed to steal credentials from infected devices and spread across connected systems.
Gurucul published threat research reporting the discovery of malicious payload delivery in the Guardrails-AI PyPI package. The reference indicates the discovery as a distinct supply-chain security event affecting a Python package ecosystem component.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcecommunity.gurucul.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.