Skip to content

OpenAI

Disclosed May 14, 20264 months agoUnverified

TanStack npm supply chain attack reached two OpenAI employee devices and internal repos

OpenAI said two employees' devices were compromised in the Mini Shai-Hulud supply chain campaign attributed to TeamPCP, with credential-focused exfiltration from a limited set of internal source repositories. It rotated code-signing certificates and said customer data and production systems were not affected.

What is known

People affectedNot stated in the sources we have
DisclosedMay 14, 2026
AttackSupply chain
Data exposedCredentials and tokens, Source code
SectorAI · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Part ofTanstack (2026)

Sources

Notices filed

WhereFiledPeople
ResearchtotalMay 14
ResearchtotalMay 14

Same campaign

Other breaches at OpenAI

History of this record
  • 2026-09-25 · summary: OpenAI said two employee devices were compromised in the Mini Shai-Hulud TanStack npm supply-chain attack, exposing limited credentials from internal code repositories and code-signing certificates, which it rotated. It found no customer da to OpenAI said two employees' devices were compromised in the Mini Shai-Hulud supply chain campaign attributed to TeamPCP, with credential-focused exfiltration from a limited set of internal source repositories. It rotated code-signing certifi · seed source
  • 2026-09-25 · title: OpenAI says TanStack supply-chain attack hit employee devices and signing certs to TanStack npm supply chain attack reached two OpenAI employee devices and internal repos · seed source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about OpenAI

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.