TanStack had two-factor on every maintainer account. They used npm OIDC trusted publishing, the control meant to retire long-lived publish tokens. Their releases shipped with valid provenance attestations.

On May 11, 2026, an attacker published 84 malicious versions across 42 @tanstack/* packages anyway, including @tanstack/react-router, which moves over 12 million weekly downloads (TanStack postmortem, Snyk). The malicious versions carried the same kind of valid provenance signal the legitimate releases do.

OpenAI is the downstream consequence. Two employee devices installed a poisoned @tanstack/* version. OpenAI says the incident did not affect customer data, production systems, intellectual property, or deployed software, but it did expose limited credential material and signing-certificate-related material in repositories accessible to those employees. OpenAI is re-signing its applications with new certificates and has given macOS users until June 12, 2026 to update before older desktop app versions may stop functioning (OpenAI, BleepingComputer). They were not the target. They were a consumer of an npm package.

This is the throughline I have been writing toward for months. MCP Servers Have an npm Problem flagged that AI tool registries were replaying npm's 2014. n8n Shipped Three Patch Waves in Two Months walked through what happens when self-hosted automation eats those advisories. The TanStack incident is the one that closes the loop. It says the attack surface stopped being credentials a while ago. It is the build pipeline.

Here is what "everything right" meant, and what failed:

  • 2FA on maintainers. Held. No npm token was stolen. No maintainer account was compromised.
  • OIDC trusted publishing. Held against stolen long-lived tokens, but not against attacker code already executing inside the publishing runner. The runner minted a short-lived publish token in memory when id-token: write was set, and attacker code running in the same job read that token straight out of /proc/<pid>/mem.
  • Signed provenance. Held. The attacker used the legitimate publishing path, so the malicious packages were validly attested. Provenance proves origin; it does not prove intent.
  • Pinned dependencies, scoped permissions. Did not save them. The defect was a pull_request_target workflow that ran fork code in the base repository's cache scope. It is a pattern GitHub's own security guidance has warned about for years (TanStack hardening followup).

The OpenAI blast radius is the part that should change how the rest of us think about this. Their statement says only limited credential material was exfiltrated, no customer data, no production systems, no IP, no software altered. That is the good outcome. The bad outcome is what those two devices could reach: source-code repositories containing signing-certificate-related material (TechCrunch). Two employee laptops, one open-source dependency, and now every macOS ChatGPT user has a software update deadline. OpenAI also notes this was the second certificate-rotation event in two months, following the Axios developer-tool compromise in March, which had already pushed the company toward additional controls (OpenAI Axios response, OpenAI TanStack response).

The actionable takeaway is short. Trusted publishing is necessary and not sufficient. Audit the pull_request_target workflows in your org this week, especially any that touch the Actions cache. Purge caches on repositories where untrusted code could have written into a cache later restored by release jobs. Split build and publish jobs so the job with id-token: write does not restore or execute artifacts influenced by untrusted pull requests. Treat OIDC tokens as runtime secrets that leak through process memory, not as credentials that live in a vault. Plan for code-signing certificate rotation as a recurring event, not an emergency. And read Your MCP Configs Are an Attack Surface Now if you have not, because the same campaign hit there too.


See also: MCP Servers Have an npm Problem, n8n Shipped Three Patch Waves, Your MCP Configs Are an Attack Surface.