All Breaches
May 14, 2026 Verified Sensitive Record Technology

OpenAI TanStack 2026 Data Breach

The OpenAI TanStack 2026 data breach occurred when malicious TanStack packages in the Mini Shai-Hulud supply-chain campaign affected two OpenAI employee devices and produced credential-focused exfiltration activity in a limited subset of internal source-code repositories available to those employees. OpenAI disclosed the incident on May 14, 2026, and said it quickly isolated the affected systems and identities.

The company said only limited credential material was successfully transferred from the repositories and no other information or code was affected. It found no unauthorized impact to customer data, production systems, intellectual property, or deployed software. Because OpenAI explicitly confirmed two impacted employees, pwnCount and totalRecords are 2; hundreds of malicious packages are not a user count.

How Was the Incident Confirmed?

OpenAI's official “Our response to the TanStack npm supply chain attack” advisory directly confirms two affected corporate employee devices, unauthorized access in limited internal repositories, and credential-focused exfiltration. The company conducted a forensic investigation with a third-party incident-response firm, isolated the relevant accounts and devices, and published clear boundaries for the affected data.

BleepingComputer and The Hacker News independently reported the company disclosure, corroborating the two devices, limited credential transfer, unaffected customer and production areas, and precautionary code-signing certificate rotation. Both reports connect the event to the broader Mini Shai-Hulud campaign. LeakData does not add the actor's claims about other companies or packages to OpenAI's scope.

How Did the TanStack Chain Reach OpenAI?

The Mini Shai-Hulud campaign injected malicious code into release flows for TanStack and other open-source projects to collect secrets from developer environments. The payload searched for developer access such as GitHub and npm tokens, cloud credentials, Kubernetes secrets, SSH keys, and environment files. Use of trusted packages and normal distribution channels allowed it to propagate quickly to downstream organizations.

OpenAI observed activity on two employee devices consistent with the malware's publicly documented behavior. Unauthorized access and credential-focused exfiltration occurred in a limited subset of internal source-code repositories available to those employees. Because the company did not publish the exact package version or execution time that provided initial access, breachDate uses the May 14 disclosure date.

What Data Was Affected?

The confirmed data class is limited credential material successfully transferred from internal source-code repositories. OpenAI separated repository access from actual exfiltration by stating that no other information or code was affected. LeakData therefore records internal-repository access as incident context but does not claim that source code or intellectual property was stolen.

The affected repositories also contained code-signing certificates used for OpenAI products on iOS, macOS, and Windows. The company found no evidence that the certificates had been used to sign malicious software, but revoked and replaced them to remove potential risk. Certificates are described as potentially exposed, not as credentials with confirmed malicious use.

Were Customer Data and Production Systems Affected?

OpenAI confirmed that customer or user data was unaffected, production systems were not accessed, and deployed software was not modified without authorization. Intellectual property was also excluded from the compromised-data scope. These boundaries prevent ChatGPT users, API customers, or OpenAI's total workforce from being used as pwnCount.

The company found no evidence that the limited stolen credential material was used in follow-on attacks. It isolated impacted systems and identities, revoked user sessions, rotated all credentials across affected repositories, temporarily restricted deployment workflows, and audited user and credential behavior. These actions form the verified containment boundary that kept the incident from progressing into production.

What Does the Application Certificate Rotation Mean?

After replacing certificates, OpenAI asked macOS users of ChatGPT Desktop, Codex App, Codex CLI, and Atlas to update before June 12, 2026. Once the old certificates were revoked, Apple's notarization controls could block new downloads or launches signed with the previous certificate. This required user action does not indicate that customer data was stolen.

Windows and iOS users did not need to take incident-related action. OpenAI's broad rotation of macOS, Windows, iOS, and Android signing material was precautionary; the company did not detect a fake OpenAI application signed with the exposed certificates. LeakData presents the update requirement as response guidance, not as a separate end-user breach.

How Should This LeakData Record Be Read?

The pwnCount and totalRecords values are based on the two impacted employees explicitly confirmed by OpenAI. Two devices and two employees describe the same verified scope; repository, certificate, and malicious-package counts are not added to the number of people. importedRecordCount is zero, and no employee identity, secret, or source code is imported into LeakData.

Readers should understand the verified event as two employee devices, limited internal-repository access, and exfiltration of limited credential material. Customer data, production systems, intellectual property, and deployed software were unaffected, and no certificate abuse was detected. If new forensic findings are published, the data classes and scope can be reassessed against original sources.

2
Affected Accounts
3
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

3
Limited credential material
Internal source code repository access
Potentially exposed code-signing certificates

Additional Information

Added DateJuly 27, 2026
Breach DateMay 14, 2026
Domainopenai.com
SourceTanStack Mini Shai-Hulud compromise of two employee devices
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information