OpenAI hit by supply chain attack linked to malicious TanStack packages

2026-05-16T14:51:55Z0b375c4951b73a4450312bd26b6ad9514d141878055cdc5f5946589b14cdbc67
OpenAITanStackTeamPCPbitlocker-bypasscisa-kevcisco-catalyst-sd-wancredential-exposurectfmoncve-2026-20182cve-2026-41702cve-2026-42897cve-2026-42945cve-2026-46300exchange-serverfragnesiagreenplasmalinux-kernelnginxnginx-riftpackage-tamperingprivilege-escalation','pwn2own','zero-day','ghostwriter','frostysupply-chainvmware-fusionwindows-zero-dayyellowkey

What happened

Multiple high-impact incidents and disclosures: OpenAI was hit by a TanStack supply-chain attack (attributed to TeamPCP) that compromised two employee devices and exposed credentials stored in internal source code repositories. Microsoft confirmed active exploitation of an Exchange Server zero-day (CVE-2026-42897, XSS, CVSS 8.1). CISA added a critical Cisco Catalyst SD‑WAN flaw (CVE-2026-20182, CVSS 10.0) to its Known Exploited Vulnerabilities catalog. Researchers disclosed a new Linux kernel local‑root bug dubbed Fragnesia (CVE-2026-46300). A critical 18‑year‑old NGINX heap buffer overflow (C

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
0b375c4951b73a4450312bd26b6ad9514d141878055cdc5f5946589b14cdbc67
Enrichment time
2026-05-16T14:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · OpenAI hit by supply chain attack linked to malicious TanStack packages · Baitaphish