05:20 AM EDT, 05/14/2026 (MT Newswires) -- Microsoft-backed (MSFT) OpenAI said Wednesday it found no evidence that customer data, production systems, intellectual property, or software were compromised following a supply chain attack involving the TanStack npm open-source library.

The company said two employee devices were affected by the broader "Mini Shai-Hulud"malware campaign, resulting in limited credential-focused exfiltration activity involving a small subset of internal source code repositories.

OpenAI said it responded by isolating affected systems, revoking user sessions, rotating credentials, temporarily limiting code-deployment workflows, and hiring a third-party digital forensics firm.

The company is also rotating code-signing certificates as a precaution, requiring macOS users to update their applications, while no action is needed for Windows or iOS users, OpenAI said.

Microsoft has invested billions into ChatGPT maker OpenAI.

Ämnen i artikeln

Microsoft

Senast

405,21

1 dag %

0,00%

1 dag

1 mån

1 år

Marknadsöversikt

1 DAG %

Senast

1 mån