Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    OpenAI Hit by TanStack Supply Chain Attack

    May 16, 2026

    Elon Musk Absolutely Obsessed With Tweets From Random Guy In India Who Constantly Glazes Him, Analysis Shows

    May 16, 2026

    Adobe InDesign (2026) review | TechRadar

    May 16, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»OpenAI Hit by TanStack Supply Chain Attack
    OpenAI Hit by TanStack Supply Chain Attack
    Cybersecurity

    OpenAI Hit by TanStack Supply Chain Attack

    The Tech GuyBy The Tech GuyMay 16, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    OpenAI has disclosed the impact of the recent TanStack supply chain attack, warning that credential material was exfiltrated from internal source code repositories.

    Advertisement

    The open source web application development stack TanStack was hit on May 11, when the TeamPCP hacking group exploited security weaknesses in the package publishing process to release 84 malicious artifacts across 42 packages.

    Over 170 packages across several high-profile NPM and PyPI namespaces were compromised on the same day as part of a coordinated campaign. Developer devices were infected with the Shai-Hulud worm.

    OpenAI was one of the organizations affected downstream. Two employee devices were infected as part of the attack, and credentials and other secrets were exfiltrated from them.

    Despite its limited scope, the compromise granted the attackers access to several internal source code repositories that the two OpenAI employees had access to.

    “We confirmed that only limited credential material was successfully exfiltrated from these code repositories and that no other information or code was impacted,” OpenAI says.

    Advertisement. Scroll to continue reading.

    The company says it has rotated credentials across all affected repositories, revoked user sessions, and temporarily restricted code-deployment workflows. No customer data or intellectual property was affected in the attack, it says.

    The compromised repositories contained code-signing certificates for iOS, macOS, Windows, and Android products, and OpenAI decided to revoke the certificates and re-sign all applications.

    macOS users will need to update their applications by June 12, 2026. After that date, these products will no longer receive updates and might stop functioning properly.

    “We are updating our security certificates, which will require all macOS users to update their OpenAI apps to the latest versions. This helps prevent any risk, however unlikely, of someone attempting to distribute a fake app that appears to be from OpenAI,” the company says.

    OpenAI says it is also coordinating with platform providers to stop new notarizations and prevent the malicious use of the stolen certificates.

    “We have also reviewed all notarization of software using our previous certificates to confirm no unexpected software signing has occurred with these keys, and validated that our published software did not have unauthorized modifications. We have found no evidence of compromise or risk to existing software installations,” the company says.

    The incident, OpenAI says, occurred during the transition to hardened configurations and credentials material, which was prompted by the Axios supply chain attack that occurred at the end of March, and which affected a certificate and notarization material used to sign OpenAI’s macOS applications.

    Because the transition was implemented in phases, the two employee devices had not yet been updated with the new configurations, which would have prevented the malicious package downloads.

    Related: DigiCert Revokes Certificates After Support Portal Hack

    Related: Worries About AI’s Risks to Humanity Loom Over the Trial Pitting Musk Against OpenAI’s Leaders

    Related: Checkmarx Confirms Data Stolen in Supply Chain Attack

    Related: OpenAI Widens Access to Cybersecurity Model After Anthropic’s Mythos Reveal

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

    May 15, 2026

    In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws

    May 15, 2026

    American Lending Center Data Breach Affects 123,000 Individuals

    May 15, 2026

    Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere

    May 15, 2026

    New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation

    May 14, 2026

    Enhancing Data Center Security Without Sacrificing Performance

    May 14, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    ChatGPT Group Chats are here … but not for everyone (yet)

    November 14, 20258 Views

    Facebook updates its algorithm to give users more control over which videos they see

    October 8, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    OpenAI Hit by TanStack Supply Chain Attack

    May 16, 2026

    Elon Musk Absolutely Obsessed With Tweets From Random Guy In India Who Constantly Glazes Him, Analysis Shows

    May 16, 2026

    Adobe InDesign (2026) review | TechRadar

    May 16, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.