OpenAI caught in TanStack npm supply chain chaos after employee devices compromised


OpenAI says attackers behind the TanStack npm supply chain compromise stole internal credentials after reaching two employee devices, forcing the company to rotate signing certificates for several desktop products.

The company disclosed this week that it had been caught up in the wider “Mini Shai-Hulud” campaign targeting npm ecosystems and developer infrastructure, though it said there was no evidence that customer data, production systems, or deployed software were compromised.

Read more…
Source:  The Register News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Carderbee: APT Group use Legit Software in Supply Chain Attack Targeting Orgs in Hong Kong

    August 22, 2023

    A previously unknown advanced persistent threat (APT) group used the legitimate Cobra DocGuard software to carry out a supply chain attack with the goal of deploying the Korplug backdoor (aka PlugX) onto victim computers. In the course of this attack, the attackers used malware signed with a legitimate Microsoft certificate. Most of the victims in this ...

  • Cyber attack on Aussie energy services firm may hit UK CNI

    August 21, 2023

    Operators of critical utility infrastructure across the UK may have been affected by a developing cyber attack on the systems of Energy One, an Australia-based supplier of software and services for the energy sector. The ongoing incident was disclosed via a statement to the Australian Securities Exchange (ASX) on the morning of Monday 21 August (Sunday ...

  • Capita shares plummet 11 per cent as contractor reveals cyber attack cost £25m

    August 4, 2023

    Capita shares in slumped 11.4 per cent on Friday morning after it said a recent data breach could cost it up to £25m. The government contractor, which provides data and IT outsourcing processes, said this morning it expects a major cyber attack in March could cost it £20-25m, as an investigation nears its close. Read more… Source: City ...

  • Capita boss quits as fine looms for huge hack of confidential data

    July 31, 2023

    The chief executive of outsourcing firm Capita is to step down as the company reels from a cyber-attack that could result in a hefty fine from the UK’s information and privacy regulator. Capita said Jon Lewis would step down by the end of the year, making way for Adolfo Hernandez, the vice-president of telecommunications at Amazon ...

  • Norway government ministries hit by cyber attack

    July 24, 2023

    Norwegian authorities reported a cyber attack of unknown origin against 12 government ministries on Monday. “We have uncovered a previously unknown vulnerability in the software of one of our suppliers,” said Erik Hope, director of the Norwegian ministries’ security and service organisation, in a press statement. “This vulnerability has been exploited by an unknown actor. We ...

  • North Korea Leverages SaaS Provider in a Targeted Supply Chain Attack

    July 24, 2023

    In July 2023, Mandiant Consulting responded to a supply chain compromise affecting a US-based software solutions entity. Mandiant researchers believe the compromise ultimately began as a result of a sophisticated spear phishing campaign aimed at JumpCloud, a zero-trust directory platform service used for identity and access management. JumpCloud reported this unauthorized access impacted fewer than five ...