AI Briefing
KO

OpenAI's Response to the TanStack npm Supply Chain Attack

·2026.05.13 09:00

Key point

OpenAI announced its response to the TanStack npm supply chain attack and a macOS certificate replacement.

Details

OpenAI disclosed the status of its response to the TanStack npm supply chain attack, also known as Mini Shai-Hulud, which was discovered on May 11, 2026 UTC. The company stated that it found no evidence that user data, production systems, or intellectual property were compromised.

However, internally, limited credential material was leaked from the devices of 2 affected employees and some internal source code repositories they had access to. OpenAI isolated the devices and accounts, revoked sessions, rotated credentials across the board, and temporarily restricted code deployment workflows, while conducting an investigation together with a third-party forensics and incident response firm. Customer passwords and API keys were also not affected. No misuse of the leaked credentials or further intrusion was identified.

The affected repository contained product signing certificates, which is why OpenAI is re-signing its Windows, macOS, iOS, and Android apps with new certificates. In particular, macOS users must update their apps to the latest version by June 12, 2026, while Windows and iOS require no separate action.

The older macOS app versions are as follows.

  • ChatGPT Desktop: 1.2026.125
  • Codex App: 26.506.31421
  • Codex CLI: 0.130.0
  • Atlas: 1.2026.119.1

OpenAI explained that it has blocked new notarization under the old certificate, and that it found no signs of tampering or additional risk in existing installations. The company also stated it will more rapidly roll out package management controls such as minimumReleaseAge, which it has been deploying since the Axios incident, along with package provenance verification tools, to reduce the impact of similar supply chain attacks in the future.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.