tech
Our response to the TanStack npm supply chain attack
We recently identified a security issue involving a common open-source library, TanStack npm, that is part of a broader attack known as Mini Shai-Hulud. We found no evidence that OpenAI user data was accessed, that our production systems or intellectual property were compromised, or that our software was altered.

TL;DR
- OpenAI experienced a security incident due to a compromise in the TanStack npm open-source library.
- No OpenAI user data, production systems, or intellectual property were compromised.
- Two employee devices were impacted, with limited credential exfiltration from internal repositories.
- Code-signing certificates for Windows, macOS, and iOS were impacted.
- macOS users must update their OpenAI applications by June 12, 2026, to continue using them.
- New downloads and launches of older macOS apps signed with the previous certificate will be blocked after June 12, 2026.
- OpenAI is implementing enhanced security controls to prevent future supply chain attacks.