15/05/2026
OpenAI Confirms Security Breach Via TanStack npm Supply Chain Attack
May 15, 2026 Two employee devices at OpenAI were compromised in a sweeping software supply chain attack targeting TanStack npm, but the AI company confirmed no user data, production systems, or intellectual property were affected. On May 11, 2026 UTC, threat actors launched a campaign dubbed “Mini Shai-Hulud” a coordinated supply chain offensive orchestrated by the TeamPCP extortion gang. The attackers injected malicious code into TanStack, a widely used open-source JavaScript library, by abusing weaknesses in the project’s GitHub Actions workflows and CI/CD configuration....
OpenAI Confirms Security Breach Via TanStack npm Supply Chain Attack In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog WriterMay 15, 2026 Spread the love May 15, 2026 Two employee devices at OpenAI were compromised in a sweeping software supply chain attack targeting TanS...