AI Privacy IncidentMay 11, 2026

OpenAI internal repo and signing credential exposure via TanStack npm supply chain

Vendor: OpenAI
Product: ChatGPT Desktop, Codex, Atlas (macOS)
Severity: high
Status: confirmed-resolved
Users affected: all macOS users of OpenAI desktop applications must update before 2026-06-12 due to certificate rotation; no customer data accessed per OpenAI

Summary

On May 14, 2026, OpenAI disclosed that two employee devices were impacted by malicious npm packages from the TanStack supply chain attack that researchers tracked as Mini Shai-Hulud. The company confirmed credential-exfiltration activity in a limited subset of internal source code repositories for its iOS, macOS, and Windows products, which held signing certificates. OpenAI said it found no evidence that user data, production systems, or intellectual property were compromised, and rotated the affected certificates.

What happened

  • Researchers at Wiz, Socket, and Aikido reported that 84 malicious npm package versions were published in a six-minute window on May 11, 2026, including TanStack artifacts with more than 12 million weekly downloads.
  • OpenAI stated that two employee devices installed a malicious version before updated configurations could block it, and that the malware accessed a limited subset of internal source code repositories.
  • The impacted repositories held signing certificates for OpenAI's iOS, macOS, and Windows desktop products, per OpenAI's disclosure.
  • OpenAI said it rotated the affected certificates and coordinated with platform vendors to block use of the previous credentials.
  • macOS users must update OpenAI desktop apps before June 12, 2026, after which older builds will fail Apple's notarization checks.

Timeline

  • 2026-04-29 - First wave of malicious npm packages published in the broader campaign, per Wiz.
  • 2026-05-11 - 84 TanStack-related malicious package versions published; two OpenAI employee devices installed an affected version.
  • 2026-05-14 - OpenAI publishes disclosure confirming employee device compromise and credential exfiltration.
  • 2026-06-12 - Deadline for macOS users to update OpenAI desktop apps before signing certificates expire.

What the vendor has confirmed

OpenAI stated it "observed activity consistent with the malware's publicly described behavior, including unauthorized access and credential-focused exfiltration activity, in a limited subset of internal source code repositories." The company said it found "no evidence that OpenAI user data was accessed, that our production systems or intellectual property were compromised, or that our software was altered." Listed remediation included credential rotation, CI/CD secret hardening, npm minimumReleaseAge controls, and additional package provenance validation.

Broader context

A self-propagating npm worm affecting widely depended-on libraries puts every downstream vendor's build environment in the blast radius of a single maintainer compromise. The risk profile rises when that environment also holds signing material for end-user applications, since the same credential exfiltration can threaten the integrity of binaries running on customer machines.

Sources

Selvam Sivakumar
Written by

Selvam Sivakumar

Founder, Elephas.app

Selvam Sivakumar is the founder of Elephas and an expert in AI, Mac apps, and productivity tools. He writes about practical ways professionals can use AI to work smarter while keeping their data private.

Related Resources

news

ChatGPhish: Your Trusted AI Just Became the Phishing Surface

The ChatGPhish vulnerability turns any web page into a ChatGPT phishing attack the moment you ask it to summarize. What leaks with zero clicks, why the cloud assistant is the attack surface, and how to cut the risk.

9 min read
news

OpenAI Is Accused of Sharing ChatGPT Chats With Meta and Google

A California class action accuses OpenAI of allegedly routing ChatGPT query data to Meta and Google through Meta Pixel and Google Analytics. What the suit claims, why the leak vector is the website and not the model, and whether ChatGPT is safe for sensitive work.

7 min read
news

Claude Mythos Release: What It Means for Your Private Files

Anthropic is withholding Claude Mythos on cyber-safety grounds, but the public release lands in weeks. Here is what that means for the documents you put into AI tools, and the one move worth making first.

8 min read
news

Starlink Updated Its Privacy Policy on January 15. If You Don't Opt Out, Your Data Trains AI.

On January 15, 2026, SpaceX updated the Starlink Global Privacy Policy to allow customer data, including audio, video, and shared files, to be used for AI training. A breakdown of what changed, who's affected, and what to do today.

9 min read