tech

Our response to the TanStack npm supply chain attack

We recently identified a security issue involving a common open-source library, TanStack npm, that is part of a broader attack known as Mini Shai-Hulud. We found no evidence that OpenAI user data was accessed, that our production systems or intellectual property were compromised, or that our software was altered.

Our response to the TanStack npm supply chain attack

TL;DR

  • OpenAI experienced a security incident due to a compromise in the TanStack npm open-source library.
  • No OpenAI user data, production systems, or intellectual property were compromised.
  • Two employee devices were impacted, with limited credential exfiltration from internal repositories.
  • Code-signing certificates for Windows, macOS, and iOS were impacted.
  • macOS users must update their OpenAI applications by June 12, 2026, to continue using them.
  • New downloads and launches of older macOS apps signed with the previous certificate will be blocked after June 12, 2026.
  • OpenAI is implementing enhanced security controls to prevent future supply chain attacks.