OpenAI Revokes macOS Cert After Axios Supply Chain Attack
Curated by the Inblix editorial team
OpenAI disclosed a security issue linked to a compromised third-party library, Axios, part of a broader industry supply chain attack. A GitHub Actions workflow for macOS app signing downloaded and executed a malicious version of Axios. While the signing certificate may not have been exfiltrated, OpenAI is revoking and rotating it as a precaution. No evidence of user data access, system compromise, or software alteration was found. Users must update their macOS apps by May 8, 2026, to maintain functionality and security. Older versions of ChatGPT Desktop, Codex, and Atlas will stop working. OpenAI engaged a forensic firm and is working with Apple to prevent new notarization with the old certificate. Why it matters: This incident highlights the growing risk of software supply chain attacks targeting development tools and the importance of rapid certificate rotation to maintain trust in signed applications.
💡 Key Takeaways
- A compromised version of the Axios developer library was executed in an OpenAI macOS app signing workflow, but no user data or intellectual property was accessed.
- OpenAI is revoking its macOS code signing certificate as a precaution, requiring all users to update their apps by May 8, 2026, or risk losing functionality.
- Third-party digital forensics confirmed no unauthorized modifications to OpenAI software, and the company is working with Apple to prevent old certificates from being used.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.