Mini Shai-Hulud supply-chain attack compromises OpenAI devices and triggers macOS certificate rotation
The Mini Shai‑Hulud campaign began on May 11, 2026, after attackers compromised the TanStack npm release infrastructure and published 84 malicious packages across 42 repositories. Two OpenAI employee devices downloaded the poisoned dependencies before new supply‑chain protections were deployed, allowing the threat actors to exfiltrate limited internal credentials, including code‑signing certificates used for macOS versions of ChatGPT Desktop, Codex App, Codex CLI and Atlas. OpenAI responded by isolating the machines, revoking sessions, rotating the affected certificates and requiring macOS users to update the applications by June 12, 2026; it reported no evidence that customer data, production systems or core intellectual property were compromised.
The attack is linked to the threat group TeamPCP, which has been identified as the operator of the broader Mini Shai‑Hulud operation that poisoned npm and PyPI packages for a range of AI and enterprise software vendors such as Mistral AI, UiPath and Guardrails AI. In the aftermath, TeamPCP advertised the sale of roughly 5 GB of internal Mistral AI repositories—including training, fine‑tuning and benchmarking code—on a hacking forum for $25 000, threatening to publicly leak the data if no buyer emerges. Mistral AI confirmed that some SDK packages were briefly contaminated but affirmed that hosted services, user data and core systems remained intact.
These incidents highlight a growing wave of supply‑chain attacks across the JavaScript ecosystem, with additional threats reported against other npm packages (e.g., node‑ipc and a crypto‑js‑mimicking package) that leverage malicious publish credentials and Tor‑based command‑and‑control to steal developer secrets.