tech

OpenAI Among the Companies Affected by TanStack Breach

OpenAI has warned Mac users to update desktop apps after attackers compromised TanStack & other npm packages to spread credential-stealing malware

OpenAI Among the Companies Affected by TanStack Breach

TL;DR

  • A large-scale software supply chain attack, Mini Shai-Hulud, compromised open-source libraries including TanStack.
  • Attackers exploited GitHub Actions vulnerabilities to steal OpenID Connect tokens and publish malicious package versions.
  • OpenAI confirmed that two employee systems were impacted, and they are taking steps to secure their environment.
  • The malware contains credential-stealing capabilities targeting CI/CD tokens, cloud credentials, and more.
  • The malware exhibits worm-like capabilities, spreading through the npm ecosystem by publishing additional malicious packages.
  • The malware avoids exfiltrating data if Russian language settings are detected on a system.
  • OpenAI has warned Mac users to update their desktop applications.
  • TanStack has issued an all-clear regarding the security of its repositories and packages after a security sweep.