TanStack npm Supply Chain Attack Affects OpenAI and AI Ecosystem – May 2026
A multi-stage software supply chain attack originating with the compromise of the TanStack npm library has propagated through npm and PyPI ecosystems to a downstream Nx Console VS Code extension. GitHub confirmed attackers accessed approximately 3,800 internal repositories via the compromised extension, and multiple AI companies, including OpenAI, are reported affected. OpenAI has advised macOS users to update software. Attribution, full data exfiltration scope, and containment status remain under investigation.
AI-generated from linked source reports. See our correction policy.
Impact verdict
High impact. Confirmed impact has expanded from an initial open-source library compromise to a multi-stage supply chain intrusion at a major code-hosting platform (GitHub, with approximately 3,800 internal repositories accessed via a downstream compromised VS Code extension) and reportedly affects multiple AI companies, including OpenAI. This raises exposure across the AI development ecosystem and core developer infrastructure, though confirmed data exfiltration, financial loss, and customer impact details remain undisclosed, and the supply chain nexus to insured loss triggers remains indirect. Potential impact remains high given the scale of GitHub's confirmed internal repository exposure and the expanding campaign scope, pending further disclosure of data loss and containment status.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialGeographic Zone Matches
3 active matches
- TRIA Certified AreasRule-basedConfidence 100%
- Pacific Ring of FireRule-basedConfidence 100%
- Caribbean Hurricane ZoneRule-basedConfidence 100%
Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.
Affected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts