According to Odaily, OpenAI confirmed that its internal environment was targeted by a supply chain attack involving a malicious NPM package linked to TanStack, affecting two employee devices. While user data and core code remain unaffected, attackers stole partial internal repository access credentials, including code-signing certificates used for iOS, macOS, and Windows products.
To prevent misuse of stolen certificates, OpenAI has initiated defensive certificate rotation and mandated all macOS users of ChatGPT Desktop, Codex, and Atlas browser upgrade to the latest version by June 12, 2026. On that date, old certificates will be revoked and older versions will be blocked from launching or installing.
Related News
ChatGPT adds another legal lawsuit! Accused of secretly leaking users’ chat content to Meta and Google
OpenAI: No User Data Breach in TanStack Supply Chain Attack
AI suite supply chain sees two-way attacks: Mistral and fake OpenAI models are both compromised