2026 OpenAI — TanStack npm supply-chain attack; two employee devices, repo credentials exposed (May)
Data compromised
Limited internal repository credentials; exposed code-signing certificates (rotation underway); no attested end-user ChatGPT content breach per OpenAI
Technical writeup
On 14 May 2026, OpenAI publicly confirmed that two employees’ devices were compromised during the Mini Shai-Hulud / TeamPCP TanStack npm supply-chain campaign that poisoned hundreds of trusted npm and PyPI packages earlier that week. OpenAI’s incident write-up described malware-consistent credential-focused exfiltration against a limited subset of internal source-code repositories those employees could reach, followed by isolation, session revocation, credential rotation, and restricted deployment workflows while a third-party forensics firm assisted. The company said no evidence showed stolen repository credentials were reused for further attacks, but code-signing certificates for macOS, Windows, iOS, and Android OpenAI apps were exposed—prompting precautionary rotation and a 12 June 2026 deadline for macOS users to refresh desktop clients under Apple notarization rules. BreachHistory classifies this as a developer-supply-chain spillover rather than a consumer ChatGPT database leak; related package rows live under `package-supply-incidents.json` for the underlying TanStack/npm wave.
Root cause
Malicious TanStack/npm package compromise (TeamPCP Mini Shai-Hulud campaign) leading to credential theft from two employee endpoints with access to limited internal repos
References
- https://www.bleepingcomputer.com/news/security/openai-confirms-security-breach-in-tanstack-supply-chain-attack/
- https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/
- https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/