Our response to the TanStack npm supply chain attack

OpenAI
OpenAI addressed a supply chain attack via TanStack npm that compromised two employee devices, though no user data or software were impacted.

Summary

OpenAI recently identified a security incident involving the TanStack npm library, linked to the Mini Shai-Hulud attack. While two employee devices were impacted, resulting in limited credential exfiltration from internal repositories, OpenAI confirmed that no user data, intellectual property, or production systems were compromised. As a precaution, the company is rotating code-signing certificates for its software; macOS users are required to update their applications before June 12, 2026, to ensure continued functionality and security.

(Source:OpenAI)