TanStack supply chain was poisoned, and they lost all internal credentials but still claim that core data was unaffected? I know this kind of statement well.

View Original
MeNews
OpenAI suffers supply chain attack leaking signing certificates, macOS applications across the board will be forced to update next month
OpenAI has confirmed that its internal network suffered a malicious NPM package supply-chain attack targeting TanStack. Two employees’ devices were infected. Core data was not affected, but internal credentials and code-signing certificates were stolen. To prevent application forgery, certificate rotation will be carried out. macOS users must upgrade before 2026-06-12, and the old certificates will be revoked. iOS/Windows clients and key security are unaffected; updates must be completed within the grace period.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned