Skip to content
OpenAI says no user data breached after security issue with open

OpenAI says no user data breached after security issue with open

Ground.News May 14, 2026

OpenAI said the damage was limited to the employees’ devices, and did not affect user data nor its production systems, and none of its intellectual property was stolen.

OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution.

Two corporate laptops, some credential material, and a forced macOS app update. The interesting part is how the malicious packages got published in the first place: not by a stolen npm password, but by TanStack’s own legitimate release pipeline, after the attacker code took over the runner mid-build. OpenAI said on Wednesday that it found […] This story continues at The Web

OpenAI said it found no evidence that user data was accessed after a supply-chain attack involving the TanStack npm library. The incident has renewed concerns the security of open-source software, as researchers warn that malicious npm packages can expose developer credentials

May 14 (Reuters) – OpenAI ​said ‌on Wednesday ‌it ​found ⁠no ⁠evidence that its ​user ⁠data ⁠was accessed ​after ​a security issue ‌involving ⁠a supply-chain attack ⁠on ‌TanStack ⁠npm, ​an ‌open-source library. (Reporting ​by ⁠Gnaneshwar Rajan in ​Bengaluru)

OpenAI reported no user data compromise after a supply-chain attack targeting the TanStack npm library, part of the broader Mini Shai-Hulud campaign.

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (2)

Tools (1)