Son Dakika
TRSeferihisar Belediye Başkanı İsmail Yetişkin görevden uzaklaştırıldıTRApple, Yapay Zeka Tehditleri Nedeniyle Güvenlik Güncellemesini Erken YayınladıTRRusya'dan Türkiye'ye Orman Yangınları İçin Destek: İki Uçak GönderiliyorTRElektrik direğine çarpan otomobilin sürücüsüne yardım etmek isterken akıma kapıldı: 1 ölü, 1 ağır yaralıTRDMM'den NATO Zirvesi Sahte Başvuru UyarısıTRMİT Başkanı Kalın, Irak Cumhurbaşkanı Amedi ile GörüştüTRİran Meclis Başkanı Kalibaf: Petrol yaptırımları kaldırıldı ve petrolü yüzde 20 daha pahalı satıyoruzTRMicrosoft Xbox Game Pass İçin Yeni Yayıncılık Anlaşmalarını Askıya AldıTRTürkiye ve Katar arasında uydu projesi anlaşması imzalandıTRİsrail'in Lübnan Saldırılarında Can Kaybı 4 Bini AştıTRSeferihisar Belediye Başkanı İsmail Yetişkin görevden uzaklaştırıldıTRApple, Yapay Zeka Tehditleri Nedeniyle Güvenlik Güncellemesini Erken YayınladıTRRusya'dan Türkiye'ye Orman Yangınları İçin Destek: İki Uçak GönderiliyorTRElektrik direğine çarpan otomobilin sürücüsüne yardım etmek isterken akıma kapıldı: 1 ölü, 1 ağır yaralıTRDMM'den NATO Zirvesi Sahte Başvuru UyarısıTRMİT Başkanı Kalın, Irak Cumhurbaşkanı Amedi ile GörüştüTRİran Meclis Başkanı Kalibaf: Petrol yaptırımları kaldırıldı ve petrolü yüzde 20 daha pahalı satıyoruzTRMicrosoft Xbox Game Pass İçin Yeni Yayıncılık Anlaşmalarını Askıya AldıTRTürkiye ve Katar arasında uydu projesi anlaşması imzalandıTRİsrail'in Lübnan Saldırılarında Can Kaybı 4 Bini Aştı
Newsgather
GeriHackers Target Open Source Projects in Latest Supply-Chain Attacks
Hackers Target Open Source Projects in Latest Supply-Chain Attacks
Teknoloji
TechCrunch14.05.2026Teknoloji3 dk okumaUnited States

Hackers Target Open Source Projects in Latest Supply-Chain Attacks

Hızlı Bakış

Hackers compromised open source projects, including TanStack, to spread malware through updates, affecting dozens of companies, with OpenAI confirming employee devices were impacted but no user data breached.

Yapay zekâ özeti

Neden Önemli?

Recent string of supply-chain attacks targeting open source software projects.

Yazı boyutu

Earlier this week, hackers hijacked several open source projects used by dozens of companies and pushed updates designed to spread malware. This is the latest in a string of recent supply-chain attacks targeting software developers and their projects. On Wednesday, OpenAI confirmed that two employees had their devices “impacted by this attack.” But, after an investigation, the company said in a blog post that it found “no evidence that OpenAI user data was accessed, that our production systems or intellectual property were compromised, or that our software was altered.” OpenAI said that employees’ devices were compromised by an earlier attack on TanStack, a popular open source library that helps developers build web apps. On Monday, TanStack disclosed the attack and published a postmortem, saying hackers published 84 malicious versions of its software during a six-minute window. The project said a researcher detected the attack within 20 minutes. The malicious TanStack versions included malware that was designed to steal credentials from computers that the software was installed on and to self-propagate to spread to other systems. On its part, OpenAI said that it saw unauthorized access and theft of credentials “in a limited subset of internal source code repositories to which the two impacted employees had access.” According to the AI giant, “only limited credential material” was taken from the affected code repositories. As a precaution, given that the affected repositories contained digital certificates used to sign OpenAI’s products, the company said it’s rotating the certificates “as a precaution,” which will require macOS users to update the app. “We have found no evidence of compromise or risk to existing software installations,” the company wrote. It's not clear who is behind the TanStack attack. Some of the past supply-chain hacks have been attributed to a hacking gang known as TeamPCP, a group that was itself a target of hackers. But there have been other groups that have employed the same tactics against other projects. In March, North Korean hackers hijacked Axios, a popular open source development tool, and pushed malware that could have infected millions of developers. And in May, Chinese hackers were accused of a similar attack targeting thousands of Windows computers running disc-imaging software Daemon Tools. In these attacks, instead of targeting specific companies, hackers take over open source projects and push out malware disguised as innocuous regular updates. This allows them to potentially compromise dozens of targets with just one hack, spreading the damage across the internet.

Bundan Sonra Ne Olabilir?

Yapay zekâ öngörüsü — kesinlik taşımaz

  • Increased scrutiny of open source project security

    Muhtemel · Haftalar içinde

Açık Sorular

  • Identity of TanStack attackers
  • Full extent of impacted companies

İlgili Konular

Bu haber ilk olarak şurada yayınlandı: TechCrunch.

İlgili Haberler

Bu konuda daha fazlasupply-chain attack