Skip to content
AI HOT (Curated Pool)

OpenAI responds to TanStack npm supply chain attack and tightens security measures

OpenAI 回应 TanStack npm 供应链攻击并加强安全措施

OpenAI said its internal systems were not affected by the TanStack npm supply chain attack, revoked and re-signed related code-signing certificates, and required macOS users to update the app by June 12, 2026.

Why it matters: HKR-H/K/R all pass: an official OpenAI incident response names the TanStack npm attack, cert re-signing, and a June 12 macOS update deadline. Scope stays below p1 because OpenAI says internal systems were unaffected and impact is mainly client trust.

Read the original ↗Export Markdown