🚨 OpenAI Got Hit in the TanStack Supply Chain Attack 🚨
Two OpenAI employee devices were compromised when attackers poisoned hundreds of npm and PyPI packages. Here's what went down.
TanStack is everywhere in JavaScript and Python projects. Attackers injected malicious code into the supply chain, and anyone who pulled those packages during the compromise window got exposed. OpenAI immediately rotated their code-signing certificates, which is a huge deal. Those certs prove your software is l...