OpenAI says no user data breached after TanStack attack

SkimNews Take
The incident highlights how even companies with advanced security resources remain vulnerable to upstream supply-chain attacks targeting widely used open-source components.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- OpenAI confirmed two employees' devices were impacted by the TanStack supply‑chain attack.
- OpenAI said its investigation found no evidence that user data, production systems, or intellectual property were compromised.
- OpenAI reported that limited credential material was stolen from internal source code repositories accessed by the two employees.
- OpenAI is rotating digital certificates used to sign its products as a precaution, requiring macOS users to update the app.
- OpenAI noted that the malicious TanStack updates were published for a six‑minute window and included malware that steals credentials and self‑propagates.
Why it matters: OpenAI’s users must install a macOS update as the firm rotates signing certificates, while developers lose confidence in open‑source supply chains that now appear vulnerable to credential‑stealing malware.




