Menu

Post image 1
Post image 2
Post image 3
Post image 4
Post image 5
Post image 6
Post image 7
Post image 8
Post image 9
Post image 10
Post image 11
Post image 12
Post image 13
1 / 13
0

OpenAI caught in TanStack npm supply chain chaos after employee devices compromised

theregister·Carly Page·18 days ago
#pep0crQD
#x2f#security#openai#npm#tanstack#credentials
Reading 0:00
15s threshold

security Attackers stole a limited amount of internal credential material after malware hidden in poisoned packages reached two staff machines OpenAI says attackers behind the TanStack npm supply chain compromise stole internal credentials after reaching two employee devices, forcing the company to rotate signing certificates for several desktop products. The company disclosed  this week that it had been caught up in the wider "Mini Shai-Hulud" campaign targeting npm ecosystems and developer infrastructure, though it said there was no evidence that customer data, production systems, or deployed software were compromised. OpenAI said the incident happened during a phased rollout of new supply chain security controls introduced after a previous Axios-related incident . According to the company, the two compromised employee devices had not yet received updated package management protections that would have blocked the malicious dependency.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More