我们对 TanStack npm 供应链攻击的回应
立即更新
修正:请在 2026 年 6 月 26 日前更新您的 macOS 应用程序
我们将 macOS 用户的更新截止日期延长至 2026 年 6 月 26 日。我们一直在与 Apple 就此时间表进行协调,以保护我们的用户。使用先前证书进行的新公证已被阻止,并且我们没有发现任何证据表明有恶意软件使用任何 OpenAI 证书进行签名,或我们已发布的软件遭到未经授权的篡改。在我们完成迁移期间,这些安全措施将继续默认保护用户。您可以通过应用内更新或下方官方链接安全地进行更新。
我们最近发现了一个涉及常用开源库 TanStack npm 的安全问题,该问题是名为 Mini Shai-Hulud 的更广泛攻击的一部分。我们没有发现任何证据表明 OpenAI 用户数据被访问、我们的生产系统或知识产权受到损害,或者我们的软件被篡改。
我们已采取果断措施来保护我们的用户数据、系统和知识产权。作为回应的一部分,我们正在采取措施保护用于证明我们的 macOS 应用程序是合法 OpenAI 应用的认证流程。
请在 2026 年 6 月 12 日前更新您的 macOS 应用程序
我们正在更新安全证书,这将要求所有 macOS 用户将其 OpenAI 应用更新至最新版本。这有助于防范任何(尽管可能性极低)有人试图分发看似来自 OpenAI 的虚假应用的风险。您可以通过应用内更新或下方官方链接安全地进行更新:
ChatGPT 桌面版
Codex 应用
Codex CLI
Atlas
您信息的安全和隐私是我们的首要任务。我们致力于保持透明,并在问题出现时迅速采取行动。我们将在下方分享更多技术细节和常见问题解答。
发生了什么以及我们正在采取的措施
2026 年 5 月 11 日(UTC 时间),广泛使用的开源库 TanStack 在一次名为 Mini Shai-Hulud 的更广泛软件供应链攻击中遭到入侵。
此次攻击影响了我司企业环境中的两台员工设备。在发现恶意活动后,我们迅速展开调查、进行遏制,并采取措施保护系统。作为调查与响应工作的一部分,我们聘请了一家第三方数字取证与事件响应公司。
我们观察到,该恶意软件的行为与其公开描述的特征一致,包括在两名受影响员工有权访问的部分内部源代码仓库中,出现了未经授权的访问和以窃取凭证为目标的数据外泄活动。我们确认,仅少量凭证材料成功从这些代码仓库中被窃取,其他信息或代码未受影响。
我们立即采取行动遏制该活动。我们隔离了受影响的系统和身份信息,撤销了用户会话,轮换了受影响仓库中的所有凭证,暂时限制了代码部署工作流,并对用户及凭证行为进行了彻底审查。在调查过程中,我们未发现客户数据或知识产权受到影响的证据,分析结果也未显示攻击者利用了受影响的凭证或进行了后续访问。
受影响的源代码仓库中包含我们产品的签名证书,涉及 iOS、macOS 和 Windows 系统。因此,作为预防措施,我们正在轮换代码签名证书,这将要求 macOS 用户更新其应用程序。Windows 和 iOS 应用的用户无需采取任何操作。我们将就这些必要的更新向 macOS 用户提供进一步指导。
除轮换证书外,我们正与平台提供商协调,通过停止新的公证来防止这些证书被未经授权使用。我们还审查了所有使用先前证书进行的软件公证,以确认这些密钥未发生意外的软件签名行为,并验证了我们已发布的软件未遭未经授权的修改。目前未发现现有软件安装存在被入侵或风险的证据。
一旦我们在 2026 年 6 月 12 日完全撤销证书,macOS 安全保护机制将阻止使用先前证书签名的应用进行新的下载和启动。
Axios 事件发生后,我们加速部署了特定的安全控制措施和技术,以降低此类供应链攻击的影响。我们的安全响应包括:进一步加固 CI/CD 流水线中使用的敏感凭证材料,部署带有 `minimumReleaseAge` 等控制项的包管理器配置,以及使用额外的安全软件来验证新软件包的来源。
此事件发生在我们分阶段部署和推广这些控制措施的过程中,受影响的两位员工设备未采用更新后的配置,而该配置本可阻止下载此次新发现的含恶意软件包。
此事件反映了威胁格局的更广泛转变:攻击者正越来越多地将目标对准共享软件依赖项和开发工具,而非任何单一公司。现代软件构建在深度互联的开源库、包管理器以及持续集成和持续部署基础设施生态系统之上,这意味着上游引入的漏洞可能迅速在组织间广泛传播。我们将持续投资于验证第三方组件完整性和来源的控制措施,并加强针对此类生态系统级供应链攻击的防御能力。
常见问题解答
OpenAI 产品或用户数据是否遭到入侵?
没有。我们未发现任何证据表明 OpenAI 产品或用户数据遭到入侵或泄露。
是否发现以 OpenAI 名义签名的恶意软件?
没有。我们未发现任何证据表明有恶意软件使用 OpenAI 的证书进行签名。
我需要更改密码吗?
不需要。客户/用户的密码和 API 密钥未受影响。
此事件影响哪些平台?
我们用于 Windows、macOS、iOS 和 Android 的签名密钥受到影响。我们正在使用新证书对所有应用重新签名并发布。macOS 用户需要在 2026 年 6 月 12 日之前采取行动进行更新,以确保应用能够继续正常运行。
为什么要求我更新 Mac 应用?
更新可确保您运行的版本使用我们最新证书签名。该证书能帮助客户确认软件来自合法开发者 OpenAI。
在哪里下载更新后的 macOS 应用?
请仅通过应用内更新或以下官方网页下载 OpenAI 应用:
- ChatGPT
- Codex App
- Codex CLI
- Atlas
请勿通过电子邮件、消息、广告或第三方下载网站中的链接安装应用。对通过电子邮件、短信、聊天消息、广告、文件共享链接或第三方下载网站发送的意外“OpenAI”、“ChatGPT”或“Codex”安装程序保持警惕。
2026 年 6 月 12 日后会发生什么?
自 2026 年 6 月 12 日起,旧版 macOS 桌面应用将不再接收更新或支持,并可能无法正常运行。这些版本是使用我们旧证书签名的最后版本:
- ChatGPT Desktop:1.2026.118
- Codex App:26.506.31421
- Codex CLI:0.130.0
- Atlas:1.2026.119.1
为什么不立即撤销证书?
我们已采取措施阻止任何使用受影响公证材料的 macOS 应用进一步通过公证。这意味着任何使用受影响证书冒充 OpenAI 应用的欺诈性应用将无法获得公证,因此除非用户明确绕过这些保护,否则 macOS 安全保护将默认阻止其运行。由于使用旧证书的新公证已被阻止,且撤销证书可能导致 macOS 阻止使用旧证书签名的应用的新下载和首次启动,我们给予用户截至 2026 年 6 月 12 日的更新时间,以最大程度减少影响。此窗口期有助于降低用户风险,并允许受影响客户端通过内置更新机制进行更新,确保其得到妥善修复。我们正与合作伙伴合作,监控任何滥用签名证书的迹象,若在此期间发现恶意活动,将加快撤销证书的进程。
Our response to the TanStack npm supply chain attack
Update now
Amended: Update your macOS applications by June 26, 2026
We are extending the update deadline for macOS users to June 26, 2026. We have been coordinating with Apple on this timeline to protect our users. New notarization with the previous certificate has been blocked, and we have found no evidence of malicious software being signed with any OpenAI certificate or unauthorized changes to our published software. These safeguards continue to help protect users by default while we complete the migration. You can update safely through an in-app update or at the official links below.
We recently identified a security issue involving a common open-source library, TanStack npm, that is part of a broader attack known as Mini Shai-Hulud . We found no evidence that OpenAI user data was accessed, that our production systems or intellectual property were compromised, or that our software was altered.
We have taken decisive steps to protect our user data, systems, and intellectual property. As part of our response, we are taking steps to protect the process that certifies our macOS applications are legitimate OpenAI apps.
Update your macOS applications by June 12, 2026
We are updating our security certificates, which will require all macOS users to update their OpenAI apps to the latest versions. This helps prevent any risk, however unlikely, of someone attempting to distribute a fake app that appears to be from OpenAI. You can update safely through an in-app update or at the official links below:
The security and privacy of your information are a top priority. We’re committed to being transparent and taking quick action when issues arise. We’re sharing more technical details and FAQs below.
What happened and what we are doing
On May 11, 2026 UTC, TanStack, a widely used open-source library, was compromised as part of a broader software supply chain attack known as Mini Shai-Hulud .
Two employee devices in our corporate environment were impacted by this attack. Upon identification of the malicious activity, we worked quickly to investigate, contain, and take steps to protect our systems. As part of our investigation and response, we engaged a third-party digital forensics and incident response firm.
We observed activity consistent with the malware’s publicly described behavior, including unauthorized access and credential-focused exfiltration activity, in a limited subset of internal source code repositories to which the two impacted employees had access. We confirmed that only limited credential material was successfully exfiltrated from these code repositories and that no other information or code was impacted.
We acted immediately to contain the activity. We isolated impacted systems and identities, revoked user sessions, rotated all credentials across impacted repositories, temporarily restricted code-deployment workflows, and thoroughly scrutinized user and credential behavior. As part of our investigation, we have not observed evidence of impact to customer data, or our intellectual property, and our analysis has not identified misuse of impacted credentials or follow-on access by the threat actor.
The impacted source code repositories included signing certificates for our products, including iOS, macOS, and Windows. As a result, we are rotating code-signing certificates as a precaution, which will require macOS users to update their applications. Users do not need to take any action for Windows and iOS apps. Additional guidance will be provided to macOS users regarding these required updates.
In addition to rotating certificates, we are coordinating with platform providers to prevent any unauthorized use of these certificates by stopping new notarizations. We have also reviewed all notarization of software using our previous certificates to confirm no unexpected software signing has occurred with these keys, and validated that our published software did not have unauthorized modifications. We have found no evidence of compromise or risk to existing software installations.
Once we fully revoke our certificate on June 12, 2026, new downloads and launches of apps signed with the previous certificate will be blocked by macOS security protections.
After the Axios incident, we accelerated the deployment of specific security controls and technologies to reduce the impact of supply chain attacks such as this one. Our security response included further hardening of sensitive credential materials used in our CI/CD pipeline, deployment of package manager configurations with controls like minimumReleaseAge, and additional security software to validate the provenance of new packages.
This incident occurred during our phased deployment and rollout of these controls, and the two impacted employee devices did not have the updated configurations that would have prevented the download of the newly observed package containing malware.
This incident reflects a broader shift in the threat landscape: attackers are increasingly targeting shared software dependencies and development tooling rather than any single company. Modern software is built on a deeply interconnected ecosystem of open-source libraries, package managers, and continuous integration and continuous deployment infrastructure, which means that a vulnerability introduced upstream can propagate widely and quickly across organizations. We are continuing to invest in controls that validate the integrity and provenance of third-party components and to strengthen our defenses against these kinds of ecosystem-level supply chain attacks.
FAQ
Were OpenAI products or user data compromised?
No. We have found no evidence that OpenAI products or user data were compromised or exposed.
Have you seen malware signed as OpenAI?
No. We have found no evidence of malicious software being signed with any of OpenAI’s certificates.
Do I need to change my password?
No. Customer/user passwords and API keys were not affected.
What platforms does this affect?
Our signing keys for Windows, macOS, iOS, and Android were impacted. All of our applications are being re-signed and released with new certificates. macOS users will need to take action to update by June 12, 2026 for applications to continue functioning.
Why are you asking me to update my Mac apps?
Updating ensures you are running versions signed with our latest certificate. This certificate helps customers know that software comes from the legitimate developer, OpenAI.
Where do I download the updated macOS apps?
Only download OpenAI apps from in-app updates or the official webpages below:
Do not install apps from links in emails, messages, ads, or third-party download sites. Be cautious of unexpected “OpenAI,” “ChatGPT,” or “Codex” installers sent through email, text, chat messages, ads, file-sharing links, or third-party download sites.
What happens after June 12, 2026?
Effective June 12, 2026, older versions of our macOS desktop apps will no longer receive updates or support, and may not be functional. These versions represent the last releases signed with our outdated certificate:
- ChatGPT Desktop: 1.2026.118
- Codex App: 26.506.31421
- Codex CLI: 0.130.0
- Atlas: 1.2026.119.1
Why are you not revoking the certificate immediately?
We have worked to block any further notarization of macOS apps with the impacted notarization material. This means that any fraudulent app posing as an OpenAI app using the impacted certificate will lack notarization, and therefore will be blocked by default by macOS security protections unless a user explicitly bypasses those protections. Because new notarization with the previous certificate is blocked, and because the revocation may cause macOS to block new downloads and first-time launches of apps signed with the previous certificate, we are giving our users until June 12, 2026 to update to minimize disruption. This window will help minimize user risk and allow impacted clients to update through built-in update mechanisms, ensuring they are appropriately remediated. We are working with our partners to monitor for any indicators of misuse of the signing certificate, and will accelerate the revocation timeline if we identify malicious activity during this window.