OpenAI Revokes macOS App Certificates After North Korean Supply Chain Attack on Axios
OpenAI issued an urgent security warning on April 29, instructing all macOS users to update their apps before May 8, 2026 — or risk being locked out as the company revokes compromised code-signing certificates.
The incident traces to a supply chain attack on Axios, a widely used HTTP library. On March 31, attackers — believed to be North Korean state-sponsored hackers — compromised the lead maintainer's npm and GitHub accounts through social engineering, then injected malware into Axios versions 1.14.0 and 1.14.1. The malicious versions introduced a hidden dependency, plain-crypto-js, which functioned as a remote access trojan (RAT) targeting Windows, macOS, and Linux.
OpenAI's macOS app-signing workflow downloaded the compromised version, exposing a certificate used to sign ChatGPT Desktop, Codex, Codex CLI, and Atlas. Although OpenAI confirmed no user data or API keys were stolen, the company treated the certificate as compromised and has revoked and rotated it.
Apps signed with the old certificate will be blocked by macOS security protections by default starting May 8. Users who do not update before that date will find their apps fail to launch.
The incident illustrates how supply chain vulnerabilities in broadly adopted open-source packages can cascade into high-profile security events — even for organizations with sophisticated security postures. Full details at The Hacker News.
Related Articles
OpenAI said on April 10, 2026 that a compromised Axios package touched a GitHub Actions workflow used in its macOS app-signing pipeline. The company says no user data, systems, or software were compromised, but macOS users need updated builds signed with a new certificate before May 8, 2026.
OpenAI said a compromised Axios package reached a GitHub Actions workflow used in its macOS app-signing pipeline. The company said it found no evidence of user data or product compromise, but is rotating certificates and requiring users to update macOS apps.
OpenAI said a malicious Axios 1.14.1 package was executed in a GitHub Actions workflow used for macOS app signing. The company says it found no evidence of user-data exposure or tampered apps, but it is rotating certificates and requiring macOS users to update ChatGPT Desktop, Codex App, Codex CLI, and Atlas before May 8, 2026.
Comments (0)
No comments yet. Be the first to comment!