OpenAI Confirms Security Breach Linked to AI Malware Campaign
OpenAI said malware linked to the Shai-Hulud campaign infected two employee devices and gave attackers access to a small number of internal code storage systems.The company said it found no evidence that customer data, core systems, or company technology were affected.The disclosure follows earlier reports involving Microsoft and Mistral AI tied to the same broader malware campaign. OpenAI confirmed this week that hackers tied to the Shai-Hulud malware campaign breached parts of its internal development environment through a compromised open-source software package. The incident follows similar disclosures from Mistral AI as hackers increasingly target software tools used to build AI models and applications. In a blog post on Wednesday, OpenAI said hackers compromised TanStack npm, a software tool developers use to download and manage coding packages. The company said malware infected two employee devices, and gave attackers access to a small number of internal code storage systems before OpenAI stopped the activity. “We observed activity consistent with the malwares publicly described behavior, including unauthorized access and credential-focused exfiltration activity, in a limited subset of internal source code repositories to which the two impacted employees had access,” OpenAI wrote. The company said it found no evidence that customer data, production systems, or intellectual property were