Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A threat actor (tracked as TeamPCP by security researchers) compromised over 170 open-source npm and PyPI packages used widely in AI and enterprise software development, including TanStack, Mistral AI, and UiPath. The attack reached two OpenAI employee developer machines, exposing code-signing certificates for OpenAI’s macOS, Windows, iOS, and Android desktop applications. OpenAI states no customer data or production systems were breached, but organizations consuming any of the 170+ affected packages face potential credential theft and supply chain compromise of their own build pipelines.

Author

Tech Jacks Solutions