/script src="https://cdn.jotfor.ms/agent/embedjs/019aed6b767f7ddf8a544a9c4d673d188bcb/embed.js">
OpenAI data breach concerns emerged after the TanStack npm supply-chain attack, but no user data was accessed. The Silicon Review reports on two impacted employee devices and required macOS updates. OpenAI data breach fears have been addressed after the ChatGPT maker confirmed that no user data was compromised following a supply-chain attack on the widely-used TanStack open-source library, part of a broader campaign known as "Mini Shai-Hulud”. The company stated that after an immediate internal investigation, it found "no evidence that OpenAI user data was accessed, that our production systems or intellectual property were compromised, or that our software was altered." Two employee devices in OpenAI‘s corporate environment were impacted by the malicious activity. Investigators confirmed that only limited credential material was exfiltrated from source code repositories the two employees had access to, with no other information or code affected. The AI firm acted to contain the threat, isolating impacted systems, revoking user sessions, rotating credentials across affected repositories, and temporarily restricting code-deployment workflows. This AI cy...