TanStack supply chain poisoning + certificate rotation, this OpenAI incident shows that even the most advanced companies must guard against insiders. Not losing core data is luck, but in the future, the risk of forged applications must be closely monitored.

View Original
MeNews
OpenAI suffers supply chain attack leaking signing certificates, macOS applications will be forced to update next month
OpenAI confirms internal encounter with malicious NPM package supply chain attack targeting TanStack, two employee devices infected, core data unaffected, but internal credentials and code signing certificates stolen. To prevent forgery of applications, certificate rotation will be carried out, and macOS users need to upgrade before 2026-06-12, as old certificates will be revoked. iOS/Windows clients and key security, updates to be completed within the buffer period.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned