OpenAI says a supply-chain attack involving the TanStack ecosystem led to a breach of two employee devices, but it reports no evidence that user data was accessed. Multiple outlets describe the incident as tied to malicious packages that were distributed through open-source software, with researchers and industry observers noting the broader risk that compromised npm releases can expose developer credentials.

Bleeping Computer, SecurityWeek, and The Register report that attackers used infostealing malware to reach OpenAI’s internal environment after compromise of the software supply chain. OpenAI’s investigation identifies that limited internal credential material was taken from code repositories, according to reporting in The Register and SecurityWeek. In response, OpenAI rotated code-signing certificates for its applications as a precaution and worked to contain the activity.

TechRadar and Hacker News similarly report that two corporate employee devices were affected, while OpenAI states that production systems, intellectual property, and user data were not compromised or modified in an unauthorized manner. Mint likewise reports that OpenAI found no evidence of user data access following the incident.