OpenAI
Incident posture
Timeline
Summary
OpenAI reported that hackers compromised a popular open source library, leading to the infection of two employee devices and unauthorized access to a limited set of internal source code repositories containing signing certificates. The company said it found no evidence that user data, production systems, or intellectual property were accessed, but rotated the affected certificates as a precaution and noted that the malicious library versions were designed to steal credentials and self‑propagate.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Earlier this week, hackers hijacked several open source projects used by dozens of companies and pushed updates designed to spread malware, marking the latest in a series of supply‑chain attacks targeting software developers. On Monday, the maintainers of TanStack, a popular open source library for building web applications, disclosed that attackers had published 84 malicious versions of the library during a six‑minute window. A researcher detected the compromise within 20 minutes, and the malicious packages contained malware intended to steal credentials from infected machines and to self‑propagate to other systems.
On Wednesday, OpenAI confirmed that two of its employees had devices impacted by the TanStack breach, and an investigation revealed unauthorized access and theft of credentials in a limited subset of internal source code repositories to which those employees had access. The company communicated these findings in a blog post published on the same day. Because the affected repositories held digital certificates used to sign OpenAI’s products, the company announced it would rotate those certificates as a precaution, a step that will require macOS users to update the OpenAI application. OpenAI stated that it found no evidence that user data was accessed, that production systems or intellectual property were compromised, or that its software was altered.
The company also noted that it found no evidence of compromise or risk to existing software installations. Attribution of the TanStack attack remains unclear, though similar past supply‑chain intrusions have been linked to groups such as TeamPCP, North Korean actors targeting the Axios library, and Chinese actors targeting the Daemon Tools disc‑imaging utility. These attacks illustrate how compromising a single open source project and distributing malicious updates can enable threat actors to reach dozens of downstream targets with minimal effort.
Sources
Sources available to members: 1 source.