OpenAI employee devices breached in supply chain attack; macOS users must update the app by June 12

TL;DR AI
2 min readKey summary
OpenAI said a TanStack-related supply chain attack infected two employee devices and affected more than 170 npm packages and two PyPI packages.
The company rotated code-signing certificates, isolated impacted systems, and required macOS users to update the desktop app by June 12.
OpenAI said there is no evidence the incident affected customer data, production systems, or deployed software.
The case highlights how a developer supply chain breach can quickly create certificate and endpoint risk for a major AI company.



