INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
TanStack supply chain attack compromises OpenAI
| 2026-05-14 19:07 HIGH HIGH AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH SUPPLY CHAIN
Executive Summary
AI-generated
On May 14, 2026, a security breach occurred at OpenAI, where two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages. The attackers exploited weaknesses in GitHub Actions workflows to execute malicious code, extract tokens from memory, and publish malicious package versions through legitimate releases. This campaign is linked to the "Mini Shai-Hulud" supply-chain attack by the TeamPCP extortion gang, which targeted developers by slipping malicious updates into trusted software packages. As a precaution, OpenAI rotated its code-signing certificates for applications on macOS, Windows, iOS, and Android, with only limited credentials stolen from internal source code repositories. The company isolated affected systems and accounts, revoked sessions, and temporarily restricted deployment workflows, while conducting a forensic investigation with a third-party incident response firm.
Technical Mitigations AI-generated
• Rotate code-signing certificates for OpenAI applications on macOS to prevent potential launch or update issues due to Apple's notarization process.
• Use a secure CI/CD configuration and GitHub Actions workflows to prevent abuse of weaknesses in project repositories, as seen in the TanStack supply chain attack.
• Monitor for malicious package versions being published through legitimate releases by tracking changes in package tarballs and repository activity.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
IR
IL
RU
technologytechnology
Incident Timeline
2026/05/14
Threat actors used malicious updates to target developers by slipping malware into trusted software packages, resulting in unauthorized access and credential-focused exfiltration activity within OpenAI's internal source code repositories.
Click on any entity below to view its context and source!
infrastructure
Macos
Code signing certificates used for OpenAI products on macOS, Windows, iOS, and Android were also exposed in the incident.
This rotation will require macOS users to update their OpenAI desktop applications before June 12, 2026, as applications signed with the older certificates may not launch or receive updates due to Apple's notarization process.
infrastructure
Windows
Code signing certificates used for OpenAI products on macOS, Windows, iOS, and Android were also exposed in the incident.
infrastructure
Ios
Code signing certificates used for OpenAI products on macOS, Windows, iOS, and Android were also exposed in the incident.
infrastructure
Android
Code signing certificates used for OpenAI products on macOS, Windows, iOS, and Android were also exposed in the incident.
June 12, 2026
Threat actors used the Mini Shai-Hulud malware to target hundreds of npm and PyPI packages, including those in the TanStack supply chain, with the goal of stealing developer credentials.
Click on any entity below to view its context and source!
infrastructure
Linux
Microsoft Threat Intelligence
also reported
that it launched a Linux information-stealing tool that targeted systems running Russian-language software.
infrastructure
Windows
Windows and iOS users are not impacted and do not need to take any action.
infrastructure
Ios
Windows and iOS users are not impacted and do not need to take any action.
infrastructure
Vs Code
Security researchers say the malware also established persistence on developer systems by modifying Claude Code hooks and VS Code auto-run tasks, enabling it to survive package removal.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
Microsoft Threat Intelligence
also reported
that it launched a Linux information-stealing tool that targeted systems running Russian-language software.
Metrics
infrastructure
Macos
Affected Product
Code signing certificates used for OpenAI products on macOS, Windows, iOS, and Android were also exposed in the incident.
This rotation will require macOS users to update their OpenAI desktop applications before June 12, 2026, as applications signed with the older certificates may not launch or receive updates due to Apple's notarization process.
Metrics
infrastructure
Windows
Affected Product
Code signing certificates used for OpenAI products on macOS, Windows, iOS, and Android were also exposed in the incident.
Windows and iOS users are not impacted and do not need to take any action.
Metrics
infrastructure
Ios
Affected Product
Code signing certificates used for OpenAI products on macOS, Windows, iOS, and Android were also exposed in the incident.
Windows and iOS users are not impacted and do not need to take any action.
Metrics
infrastructure
Android
Affected Product
Code signing certificates used for OpenAI products on macOS, Windows, iOS, and Android were also exposed in the incident.
Metrics
infrastructure
Vs Code
Affected Product
Security researchers say the malware also established persistence on developer systems by modifying Claude Code hooks and VS Code auto-run tasks, enabling it to survive package removal.
Intelligence Sources
BleepingComputer
2026-05-14
OpenAI confirms security breach in TanStack supply chain attack
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:34
Comprehensive Tactical Telemetry
Highly Correlated Entities
14x
organisation
Identified Entity
Apple
entity
6x
infrastructure
Affected Product
Linux
software
3x
target region
Target Country
Russian Federation
country
3x
tactic
Cyber Operation Type
Extortion
tactic
2x
timeline
Temporal Reference
June 12, 2026
date
Contextual Telemetry
Context Block
3 METRICS
attribution
Attributing Entity
Microsoft Threat Intelligence
authority
malware
Malware Payload
Shai-Hulud
tool
general metric
Surfaces
6
surfaces
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.