OpenAI Rotates Certificates After TanStack Supply Chain Attack Hits Employee Devices
OpenAI has confirmed that two employee devices were compromised in the recent TanStack npm supply chain attack, prompting the company to rotate code-signing certificates and require macOS users to update their applications by 12 June.
In a security advisory published this week, the company said it found no evidence that customer data, production systems, or intellectual property were accessed or altered during the incident.
The compromise is related to a larger campaign known as “Mini Shai-Hulud,” which is an example of a software supply chain attack targeting commonly used packages from npm and PyPI repositories. The TanStack web application development framework, one of the many frameworks impacted by the attack, was exploited through compromised GitHub Actions caches where malicious versions of the npm package were made available.
The organization stated that the malware’s behavior was consistent with that described in public reports on this attack campaign. This involved the theft...
Copyright of this story solely belongs to informationsecuritybuzz.com. To see the full text click HERE