OpenAI said that it found no evidence that a supply chain attack on open-source library TanStack npm accessed any of its user data.
The AI firm said that it found no evidence that the attack impacted its intellectual property or production systems, with no evidence that its software was compromised or changed.
However, two employee devices were impacted by the TanStack breach; these were on OpenAI’s corporate environment.
OpenAI said that only limited credential material was exfiltrated from these corporate code repositories, insisting that no other code or data was impacted as a result of the third-party attack.
The ChatGPT founder said that it took immediate steps to isolate the impacted systems, restriction code deployment workflows temporarily to contain the attack.
Recommended reading
- OpenAI Dumps API Analytics Provider Following Data Breach
- Synnovis Updates On Data Breach From 2024 Ransomware Attack
- NHS Scotland Invests £3M in AI Anti-ransomware Software
- UK Facing 4 Major Cyber-Attacks Each Week, Warns NCSC
The firm said that macOS users will be required to update their OpenAI applications as it is rotating its code-signing certificates in response to the breach.





