LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › OpenAI Confirms Breach via TanStack Supply Chain Attack

HIGH severityReportedHow we verify

OpenAI Confirms Breach via TanStack Supply Chain Attack: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 14, 2026
OpenAI Confirms Breach via TanStack Supply Chain Attack

Reported May 14, 2026.

HIGH
Severity
2
Data types exposed
May 14, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

OpenAI has confirmed a breach resulting from a TanStack supply-chain attack, disclosed on May 14, 2026, that exposed credentials and code-signing certificates belonging to an undisclosed number of people. Check whether your account or systems were involved and change any exposed credentials or certificates immediately.

Severity & verification
HIGH severityReported
Account credentials exposed.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

OpenAI reported on May 14, 2026, that two employee devices had been compromised through a supply-chain attack on the TanStack npm library. The company stated that limited internal source code repositories were accessed and that credentials along with code-signing certificates were obtained. No customer data, production systems, or customer impact was confirmed. The incident is notable because OpenAI operates at the center of widely used AI services, where even narrow access to internal systems can raise questions about how development environments are protected.

Inside the incident

OpenAI disclosed that the compromise occurred as part of the TeamPCP 'Mini Shai-Hulud' supply-chain campaign targeting the TanStack npm library. Two employees' devices were affected, and the attackers used that access to reach limited internal source code repositories for the purpose of credential exfiltration.

The company responded by rotating the affected code-signing certificates, an action that required updates to macOS applications. The number of people whose information may have been involved remains unknown, and no further technical details on the scope or duration of access have been released.

How a breach like this happens

Supply-chain attacks on JavaScript libraries often begin when malicious code is introduced into a widely used package that developers install through package managers such as npm. Once the altered library is downloaded and executed on a developer's machine, it can read local files, harvest credentials, or establish further access without immediate detection.

These incidents typically exploit the trust placed in third-party dependencies rather than directly attacking the target organization's perimeter. Organizations that maintain internal repositories or signing keys on developer endpoints can see those assets reached if the initial compromise is not contained.

About OpenAI

OpenAI develops and operates large-scale artificial intelligence models and related services used by individuals and businesses worldwide. Organizations of this type routinely maintain source code for model training and inference systems, internal tooling, and credentials that grant access to cloud resources and signing infrastructure.

Even when customer data remains untouched, exposure of development credentials or signing certificates can affect the integrity of software distribution and require coordinated remediation across multiple products.

The information in question

OpenAI has named credentials and code-signing certificates as the data types obtained. The exact contents of the limited source code repositories that were accessed have not been disclosed.

Companies in this sector commonly store API keys, internal authentication tokens, and build-system credentials. Whether any of those additional items were present in the accessed repositories is unconfirmed.

What's at stake

For individuals, the direct risk appears limited because OpenAI has stated that no customer data was involved. For the organization, the rotation of code-signing certificates indicates that downstream software updates were necessary to restore trust in distributed applications.

Over time, such incidents can prompt broader reviews of how developer devices connect to internal repositories and how third-party libraries are vetted before use.

Were you affected?

Because OpenAI reported no customer data exposure, most users of its services are unlikely to have been directly impacted. Individuals who want to check whether their email address appears in any known public breach records can run a free exposure scan through established services that aggregate disclosed incident data.

Anyone concerned about credential reuse should ensure that passwords and tokens used on developer or work accounts are unique and regularly rotated.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyOpenAI security record
71/100
DoxxScan™ · Moderate doxx risk
C+ 71Fair record

1 reported incident on record.

See OpenAI’s full breach history →

More recent breaches

Brazilian IT Firm Service IT Breached by WorldLeaksJuly 3, 2026First Agentic AI Ransomware Attack via LangflowJuly 2, 2026JadePuffer Executes First Fully Autonomous LLM Ransomware AttackJuly 1, 2026Nissan Discloses Employee Data Breach via Oracle PeopleSoft Zero-DayJune 25, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the OpenAI Confirms Breach via TanStack Supply Chain Attack →

Source: BleepingComputer

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram