Back Ground.News OpenAI says no user data breached after security issue with open
OpenAI said the damage was limited to the employees’ devices, and did not affect user data nor its production systems, and none of its intellectual property was stolen.
OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution.
Two corporate laptops, some credential material, and a forced macOS app update. The interesting part is how the malicious packages got published in the first place: not by a stolen npm password, but by TanStack’s own legitimate release pipeline, after the attacker code took over the runner mid-build. OpenAI said on Wednesday that it found […] This story continues at The Web
OpenAI said it found no evidence that user data was accessed after a supply-chain attack involving the TanStack npm library. The incident has renewed concerns the security of open-source software, as researchers warn that malicious npm packages can expose developer credentials
May 14 (Reuters) – OpenAI said on Wednesday it found no evidence that its user data was accessed after a security issue involving a supply-chain attack on TanStack npm, an open-source library. (Reporting by Gnaneshwar Rajan in Bengaluru)
OpenAI reported no user data compromise after a supply-chain attack targeting the TanStack npm library, part of the broader Mini Shai-Hulud campaign.
To view factuality data please Upgrade to Premium
To view ownership data please Upgrade to Vantage
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
