OpenAI Confirms Breach via TanStack Supply Chain Attack: What Was Reportedly Exposed & What To Do
OpenAI has confirmed a breach resulting from a TanStack supply-chain attack, disclosed on May 14, 2026, that exposed credentials and code-signing certificates belonging to an undisclosed number of people. Check whether your account or systems were involved and change any exposed credentials or certificates immediately.
Inside the incident
OpenAI disclosed that the compromise occurred as part of the TeamPCP 'Mini Shai-Hulud' supply-chain campaign targeting the TanStack npm library. Two employees' devices were affected, and the attackers used that access to reach limited internal source code repositories for the purpose of credential exfiltration.
The company responded by rotating the affected code-signing certificates, an action that required updates to macOS applications. The number of people whose information may have been involved remains unknown, and no further technical details on the scope or duration of access have been released.
How a breach like this happens
Supply-chain attacks on JavaScript libraries often begin when malicious code is introduced into a widely used package that developers install through package managers such as npm. Once the altered library is downloaded and executed on a developer's machine, it can read local files, harvest credentials, or establish further access without immediate detection.
These incidents typically exploit the trust placed in third-party dependencies rather than directly attacking the target organization's perimeter. Organizations that maintain internal repositories or signing keys on developer endpoints can see those assets reached if the initial compromise is not contained.
About OpenAI
OpenAI develops and operates large-scale artificial intelligence models and related services used by individuals and businesses worldwide. Organizations of this type routinely maintain source code for model training and inference systems, internal tooling, and credentials that grant access to cloud resources and signing infrastructure.
Even when customer data remains untouched, exposure of development credentials or signing certificates can affect the integrity of software distribution and require coordinated remediation across multiple products.
The information in question
OpenAI has named credentials and code-signing certificates as the data types obtained. The exact contents of the limited source code repositories that were accessed have not been disclosed.
Companies in this sector commonly store API keys, internal authentication tokens, and build-system credentials. Whether any of those additional items were present in the accessed repositories is unconfirmed.
What's at stake
For individuals, the direct risk appears limited because OpenAI has stated that no customer data was involved. For the organization, the rotation of code-signing certificates indicates that downstream software updates were necessary to restore trust in distributed applications.
Over time, such incidents can prompt broader reviews of how developer devices connect to internal repositories and how third-party libraries are vetted before use.
Were you affected?
Because OpenAI reported no customer data exposure, most users of its services are unlikely to have been directly impacted. Individuals who want to check whether their email address appears in any known public breach records can run a free exposure scan through established services that aggregate disclosed incident data.
Anyone concerned about credential reuse should ensure that passwords and tokens used on developer or work accounts are unique and regularly rotated.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Brazilian IT Firm Service IT Breached by WorldLeaksFirst Agentic AI Ransomware Attack via LangflowJadePuffer Executes First Fully Autonomous LLM Ransomware AttackNissan Discloses Employee Data Breach via Oracle PeopleSoft Zero-DayLatest breaches
Read GalaxyWarden’s full analysis of the OpenAI Confirms Breach via TanStack Supply Chain Attack →
Based on public reporting
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.