TanStack Npm Supply Chain Attack — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
May 15, 2026
Last Seen
May 28, 2026

Related Threat Clusters

  • OpenAI Faces Supply Chain Attack via TanStack npm Library

    OpenAI confirmed a security breach affecting two employee devices due to a supply chain attack linked to the TanStack npm library, part of a broader campaign called Mini Shai-Hulud. The attack involved the publication…

    39 articles · Updated May 14, 2026
  • macOS Flags ChatGPT App as Malware Due to Certificate Revocation

    Mac users reported that the ChatGPT desktop app was flagged as malware by macOS's Xprotect system, which moved the app to the Trash. This issue arose after OpenAI revoked security certificates for older app versions due…

    2 articles · Updated May 29, 2026

Recent Intelligence Reports

  • Mac Saying ChatGPT is Malware? Here's Why & How to Fix It — Osxdaily · May 28, 2026
  • OpenAI Confirms Limited Impact From TanStack npm Supply Chain Attack, Urges macOS App Updates — Thecyberexpress · May 15, 2026

CVSS v3.1 Breakdown