• AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Artificial Intelligence

OpenAI Confirms Hack Linked to TanStack Attack

Akinola Ajibola by Akinola Ajibola
May 14, 2026
in Artificial Intelligence, Security
Share on FacebookShare on Twitter

It has been discovered that hackers took control of multiple open-source projects that were utilised by numerous businesses earlier this week and released updates intended to propagate malware. This is claimed to be the most recent of several recent attacks on software engineers and their projects that are referred to as “supply chain” attacks.

OpenAI acknowledged on Wednesday that this hack had greatly “impacted” the devices of two workers. However, following an inquiry, the business stated in a blog post that it had “no evidence that our production systems or intellectual property were compromised in any way, that our software was altered, or that OpenAI user data was accessed.”

A data breach brought on by a software supply chain attack that has been verified by OpenAI. The popular open-source web application library TanStack was taken over by hackers, which led to the event. OpenAI claims there is no proof that customer user data, production systems, or fundamental AI intellectual property were accessed or compromised, despite the attackers’ successful theft of internal credential material from particular code repositories.

The incident is part of a broader cyber-campaign known as “Mini Shai-Hulud.” This campaign uses compromised developer tools to distribute malware across multiple technology organizations. The attack vector involved pushing 84 malicious package versions to the TanStack library within a six-minute window. 

These packages embedded an information-stealing malware designed to extract local credentials. Two OpenAI employees downloaded the corrupted package onto their devices. As a result, the hackers gained unauthorized access to a limited subset of internal source-code repositories. The attackers exfiltrated limited credentialed data. They also exposed the digital code-signing certificates used to verify OpenAI software.

A prior attack on TanStack, a well-known open-source framework that aids developers in creating web applications, compromised the devices of staff, according to a source from OpenAI.

TanStack had revealed the attack and released a postmortem on Monday, where it claimed that during a six-minute period, hackers released 84 malicious copies of its software. According to the initiative, a researcher found the attack in less than twenty minutes. The malicious TanStack versions contained malware that was intended to self-propagate to spread to other systems and steal login credentials from computers on which the program was installed.

OpenAI claimed that it discovered credentials theft and unauthorized access “in a limited subset of internal source code repositories to which the two impacted employees had access.”

The AI giant claims that “only limited credential material” was extracted from the impacted code repositories. OpenAI stated that it is rotating the digital certificates “as a precaution,” which will require macOS users to update the program, because the impacted repositories held digital certificates used to certify OpenAI’s goods.

The business had stated that they have discovered no evidence of compromise or risk to existing software installations.

The perpetrators of the TanStack attack are unknown. A cyber gang called TeamPCP, which was also a victim of hackers, has been blamed for several of the previous supply chain breaches.

However, similar strategies have been used by other organizations against other initiatives. Axios, a well-known open-source development platform, was taken over by North Korean hackers in March, and they then distributed malware that might have affected millions of developers. Additionally, a similar attack on thousands of Windows systems running Daemon Tools, a disc imaging program, was allegedly carried out by Chinese hackers in May.

Instead of focusing on particular businesses, these attacks include hackers taking over open-source projects and releasing malware under the appearance of harmless routine updates. This enables criminals to spread the harm around the internet by possibly compromising dozens of targets with a single breach. 

Related Posts:

  • vercel-2249343327_f343ad
    Vercel Admits To Customer Data Been Stolen Before…
  • handala hackers
    FBI Warns of Handala Hackers Using Telegram for Malware
  • CISA Releases Nine ICS Advisories (18) (1)
    Palo Alto Networks Data Leak Exposes Customer Details
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…
  • Advantest_rushes_to_boost_AI_chip_tester_Bloomberg_20260128185756_Bloomberg
    Chip Tester Advantest Struck By Ransomware
  • ORJAL4DYNFOR3K2HJT2YITAO6Q
    Meta Warns of WhatsApp Security Threat
  • vercel-header-lg
    Vercel Confirms Breach After Hackers Claim to Sell…
  • WhatsApp
    WhatsApp GhostPairing Scam Lets Hackers Hijack Accounts

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: hackersopenaiTanStack
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • NCC Tackles Rising Complaints As TELCOs Commits N2.5tn Into Network Upgrades May 14, 2026
  • KongTuke Hackers Exploits Microsoft Teams To Breach Companies May 14, 2026
  • OpenAI Confirms Hack Linked to TanStack Attack May 14, 2026
  • Apple Sides With Google in EU Fight Over Opening Android to AI Rivals May 14, 2026
  • OpenAI and Apple Partnership Frays as ChatGPT iPhone Deal Faces Legal Threat May 14, 2026
  • Cisco Plans Nearly 4,000 Job Cuts While Pivoting Spending Toward AI and Cybersecurity May 14, 2026
  • New Google Accounts May Start With 5GB Free Storage Unless You Add a Phone Number May 14, 2026
  • Claude AI Helps User Recover Forgotten Bitcoin Wallet Worth Nearly $400,000 After 11-Year Hunt May 14, 2026
  • X Rolls Out History Tabs For Bookmarks, Likes, Videos, & Articles May 14, 2026
  • Anthropic Debuts Claude for Small Business Featuring Pre-Built AI Workflows & Connectors May 14, 2026
  • Google Announces New OS Verification Tool To Fight Fake OS May 14, 2026
  • Google DeepMind Is Turning the Mouse Pointer into an AI Assistant May 14, 2026

Browse Archives

May 2026
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Apr    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.