OpenAI said on Wednesday it found no evidence that its user data was accessed after a security issue involving a supply-chain attack on TanStack npm, an open-source library.
The ChatGPT-maker said it found no evidence that its production systems or intellectual property were compromised, or that their software was altered.
Two employee devices in its corporate environment were impacted after TanStack got compromised earlier this week.
Limited credential material was exfiltrated from these code repositories and no other information or code was impacted.
OpenAI isolated the impacted systems immediately and temporarily restricted code-deployment workflows.







