
In a disturbing turn of events this week, hackers infiltrated multiple open-source projects, affecting numerous businesses and deploying updates aimed at distributing malware. This incident is part of a growing trend of "supply chain" attacks that are increasingly targeting software developers and their applications. On Wednesday, OpenAI disclosed that two of its employees experienced compromised devices due to this attack. However, following an internal investigation, the company reassured its users in a blog post that it found no indications that user data was accessed, production systems were breached, or that any of its software had been altered. The breach was traced back to an earlier incident involving TanStack, a widely used open-source library for web app development. On Monday, TanStack reported the attack, revealing that during a swift six-minute window, hackers released 84 malicious versions of its software. Remarkably, a researcher managed to identify the attack within 20 minutes of its occurrence. The malicious versions of TanStack contained malware specifically designed to steal user credentials from affected computers and propagate itself to other systems. As for OpenAI, the company noted it had detected unauthorized access and credential theft in a limited number of internal source code repositories linked to the impacted employees. They confirmed that only a small amount of credential data was extracted from these repositories. As a precautionary measure, especially since the compromised repositories included digital certificates for signing OpenAI’s products, the company announced it would be rotating these certificates. This update will necessitate macOS users to refresh their applications. OpenAI emphasized that there was no evidence of compromising existing software installations, ensuring users of their security. The identity of the hackers behind the TanStack breach remains unclear. Some past supply chain attacks have been linked to a group known as TeamPCP, which itself has been a target of cyberattacks. Other hacking groups have similarly employed these tactics against various projects. In March, North Korean hackers infiltrated Axios, a well-known open-source development tool, deploying malware that threatened to infect millions. In another incident in May, Chinese hackers were implicated in an attack that targeted numerous Windows computers running Daemon Tools. These recent breaches highlight a troubling trend where hackers exploit open-source projects, pushing out seemingly harmless updates that can compromise a wide array of targets with a single attack, thereby amplifying their reach across the digital landscape.
The U.S. Justice Department has initiated legal proceedings against a Georgia resident, Samuel Tunick, who is accused of...
TechCrunch | Jul 24, 2026, 18:25
Nvidia has successfully forged a significant partnership with South Korea's SK Hynix to secure memory supplies essential...
CNBC | Jul 25, 2026, 05:15
Science Corp is poised to introduce a revolutionary retina chip in Europe, designed to restore partial vision for indivi...
Business Today | Jul 25, 2026, 01:00
The landscape of money is transforming beyond just cash or bank balances, and TechCrunch Disrupt 2026 is set to spotligh...
TechCrunch | Jul 24, 2026, 22:40
On Friday, SpaceX marked a significant achievement by successfully launching its first batch of third-generation Starlin...
TechCrunch | Jul 24, 2026, 23:40