The post OpenAI Confirms Security Breach Linked to AI Malware Campaign appeared on BitcoinEthereumNews.com. In brief OpenAI said malware linked to the Shai-HuludThe post OpenAI Confirms Security Breach Linked to AI Malware Campaign appeared on BitcoinEthereumNews.com. In brief OpenAI said malware linked to the Shai-Hulud

OpenAI Confirms Security Breach Linked to AI Malware Campaign

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

In brief

  • OpenAI said malware linked to the Shai-Hulud campaign infected two employee devices and gave attackers access to a small number of internal code storage systems.
  • The company said it found no evidence that customer data, core systems, or company technology were affected.
  • The disclosure follows earlier reports involving Microsoft and Mistral AI tied to the same broader malware campaign.

OpenAI confirmed this week that hackers tied to the Shai-Hulud malware campaign breached parts of its internal development environment through a compromised open-source software package. The incident follows similar disclosures from Mistral AI as hackers increasingly target software tools used to build AI models and applications.

In a blog post on Wednesday, OpenAI said hackers compromised TanStack npm, a software tool developers use to download and manage coding packages. The company said malware infected two employee devices, and gave attackers access to a small number of internal code storage systems before OpenAI stopped the activity.

“We observed activity consistent with the malware’s publicly described behavior, including unauthorized access and credential-focused exfiltration activity, in a limited subset of internal source code repositories to which the two impacted employees had access,” OpenAI wrote.

The company said it found no evidence that customer data, production systems, or intellectual property were compromised.

OpenAI said the impacted repositories included code-signing certificates used for products on macOS, Windows, and iOS. Those certificates help operating systems verify that software actually comes from a trusted company and has not been altered.

“As a result, we are rotating code-signing certificates as a precaution, which will require macOS users to update their applications,” the company said. “Users do not need to take any action for Windows and iOS apps. Additional guidance will be provided to macOS users regarding these required updates.”

OpenAI said macOS users must update OpenAI apps before June 12. Older versions signed with the previous certificates may stop functioning after that date.

OpenAI did not immediately respond to a request for comment by Decrypt.

The disclosure follows reports earlier this week involving Microsoft and French AI startup Mistral AI tied to the same broader malware campaign.

On Monday, Microsoft Threat Intelligence said attackers inserted malicious code into a Mistral AI software package distributed through PyPI, a platform developers use to download Python software tools. According to Microsoft, the malware downloaded another malicious file designed to resemble Hugging Face’s popular Transformers library, so it would blend into AI development environments.

OpenAI said the attacks highlight growing risks across the tech industry.

“This incident reflects a broader shift in the threat landscape: Attackers are increasingly targeting shared software dependencies and development tooling rather than any single company,” they wrote.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source: https://decrypt.co/367883/openai-confirms-security-breach-ai-malware-campaign

Market Opportunity
Gensyn Logo
Gensyn Price(AI)
$0.03838
$0.03838$0.03838
-22.03%
USD
Gensyn (AI) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

KAIO Global Debut

KAIO Global DebutKAIO Global Debut

Enjoy 0-fee KAIO trading and tap into the RWA boom