OpenAI News · May 13, 2026

Our response to the TanStack npm supply chain attack

Why it matters

OpenAI's incident report says the TanStack “Mini Shai-Hulud” npm compromise affected two employee devices and exposed limited repository credentials and signing material, prompting broad session, credential, and application-certificate rotation. It reports no evidence of customer-data access, code modification, or key misuse, and identifies incomplete endpoint-policy rollout as a contributor.

My takeaway: Use package-release cooldowns and provenance checks, keep signing keys out of developer workstations, minimize repository credentials, and rehearse organization-wide credential and certificate rotation. Track staged security-control rollout explicitly so temporarily uncovered devices cannot silently become the weakest link.