{"id":240228,"date":"2026-05-14T16:25:20","date_gmt":"2026-05-14T16:25:20","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/05\/14\/openai-says-hackers-stole-some-data-after-latest-code-security-issue-techcrunch\/"},"modified":"2026-05-14T16:25:20","modified_gmt":"2026-05-14T16:25:20","slug":"openai-says-hackers-stole-some-data-after-latest-code-security-issue-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/05\/14\/openai-says-hackers-stole-some-data-after-latest-code-security-issue-techcrunch\/","title":{"rendered":"OpenAI says hackers stole some data after latest code security issue | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Earlier this week, <a rel=\"nofollow noopener\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages\/\" target=\"_blank\">hackers hijacked several open source projects<\/a> used by dozens of companies and pushed updates designed to spread malware. This is the latest in a string of recent so-called \u201csupply chain\u201d attacks targeting software developers and their projects.<\/p>\n<p class=\"wp-block-paragraph\">On Wednesday, OpenAI confirmed that two employees had their devices \u201cimpacted by this attack.\u201d But, after an investigation, the company said <a rel=\"nofollow noopener\" href=\"https:\/\/openai.com\/index\/our-response-to-the-tanstack-npm-supply-chain-attack\/\" target=\"_blank\">in a blog post<\/a> that it found \u201cno evidence that OpenAI user data was accessed, that our production systems or intellectual property were compromised, or that our software was altered.\u201d<\/p>\n<p class=\"wp-block-paragraph\">OpenAI said that employees\u2019 devices were compromised by an earlier attack on TanStack, a popular open source library that helps developers build web apps.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">On Monday, TanStack <a rel=\"nofollow noopener\" href=\"http:\/\/tanstack.com\/blog\/npm-supply-chain-compromise-postmortem\" target=\"_blank\">disclosed the attack<\/a> and published a post-mortem, saying hackers published 84 malicious versions of its software during a six-minute window. The project said a researcher detected the attack within 20 minutes. The malicious TanStack versions included malware that was designed to steal credentials from computers that the software was installed on, and self-propagate to spread to other systems.\u00a0<\/p>\n<div class=\"article-block block--callout block--right has-green-500-background-color\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\t\tDo you have more information about this supply chain attack? Or other supply chain compromises? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or <a href=\"https:\/\/techcrunch.com\/2026\/05\/14\/openai-says-hackers-stole-some-data-after-latest-code-security-issue\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">email<\/a><a href=\"https:\/\/techcrunch.com\/2026\/05\/14\/openai-says-hackers-stole-some-data-after-latest-code-security-issue\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">.<\/a>\t\t<\/div>\n<p class=\"wp-block-paragraph\">On its part, OpenAI said that it saw unauthorized access and theft of credentials \u201cin a limited subset of internal source code repositories to which the two impacted employees had access.\u201d <\/p>\n<p class=\"wp-block-paragraph\">According to the AI giant, \u201conly limited credential material\u201d was taken from the affected code repositories. As a precaution, given that the affected repositories contained digital certificates used to sign OpenAI\u2019s products, the company said it\u2019s rotating the certificates \u201cas a precaution,\u201d which will require macOS users to update the app.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe have found no evidence of compromise or risk to existing software installations,\u201d the company wrote.<\/p>\n<p class=\"wp-block-paragraph\">It&#8217;s not clear who is behind the TanStack attack. Some of the past supply chain hacks have been attributed to a hacking gang known as TeamPCP, <a href=\"https:\/\/techcrunch.com\/2026\/05\/07\/hackers-hack-victims-hacked-by-other-hackers\/\" target=\"_blank\" rel=\"noopener\">a group that was itself a target of hackers<\/a>.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">But there have been other groups that have employed the same tactics against other projects. In March, <a href=\"https:\/\/techcrunch.com\/2026\/03\/31\/hacker-hijacks-axios-open-source-project-used-by-millions-to-push-malware\/\" target=\"_blank\" rel=\"noopener\">North Korean hackers hijacked Axios<\/a>, a popular open source development tool, and pushed malware that could have infected millions of developers. And in May, <a href=\"https:\/\/techcrunch.com\/2026\/05\/05\/kaspersky-suspects-chinese-hackers-planted-a-backdoor-into-daemon-tools-in-widespread-attack\/\" target=\"_blank\" rel=\"noopener\">Chinese hackers were accused of a similar attack<\/a> targeting thousands of Windows computers running disc imaging software Daemon Tools.<\/p>\n<p class=\"wp-block-paragraph\">In these attacks, instead of targeting specific companies, hackers take over open source projects and push out malware disguised as innocuous regular updates. This allows them to potentially compromise dozens of targets with just one hack, spreading the damage across the internet.<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" target=\"_blank\" rel=\"noopener\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/05\/14\/openai-says-hackers-stole-some-data-after-latest-code-security-issue\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Earlier this week, hackers hijacked several open source projects used by dozens of companies and pushed updates designed to spread malware. This is the latest in a string of recent so-called \u201csupply chain\u201d attacks targeting software developers and their projects. On Wednesday, OpenAI confirmed that two employees had their devices \u201cimpacted by this attack.\u201d But, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":240229,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-240228","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/240228","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=240228"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/240228\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/240229"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=240228"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=240228"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=240228"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}