OpenAI stated that during a recent supply chain attack, hackers compromised employee devices and stole a small number of internal codebase credentials. However, the company emphasized that user data, production systems, and core intellectual property were not affected. Previously, multiple hackers hijacked several widely adopted open-source projects, pushing updates containing malicious code in an attempt to spread malware through the software supply chain. This represents the latest instance of recent supply chain attacks targeting software developers and their projects.
