A supply chain attack named "Mini Shai-Hulud" compromised TanStack npm packages and reached OpenAI's signing certificate infrastructure.
Attackers poisoned npm packages maintained by TanStack, a widely-used collection of JavaScript libraries in frontend development. The attack worked its way into OpenAI's signing certificates, which operating systems and users rely on to confirm that a piece of software is authentic and untampered. OpenAI disclosed the incident, detailed the protective steps it took to secure affected systems, and instructed macOS users of its apps to install updates before June 12, 2026. That deadline has now passed.
Signing certificates are a high-value target in supply chain attacks because a compromised certificate lets malicious code impersonate legitimate, trusted software, bypassing the checks most users never think to question. The fact that a company of OpenAI's scale and security investment had certificate infrastructure caught up in a poisoned dependency illustrates how indiscriminate these attacks are: they compromise the toolchain, not the target, and everyone downstream inherits the problem.
npm supply chain attacks have hit everything from color utility packages to cryptocurrency wallets over the past several years; "Mini Shai-Hulud" adds a major AI vendor's signing infrastructure to that list, and the June 12 update deadline being already elapsed raises a reasonable question about how many macOS machines remain unpatched.