OpenAI Rotates macOS Certificates After Axios Supply-Chain Compromise

OpenAI’s macOS app-signing process executed a malicious Axios package version 1.14.1 during a supply-chain attack linked to North Korean group UNC1069, exposing code-signing certificates used for ChatGPT Desktop, Codex, and other apps. The company found no evidence that user data, systems, or software were compromised, but the incident breaks the assumption that CI workflows are safe from supply-chain malware execution. The Axios compromise involved malicious versions live for about three hours after attackers hijacked the maintainer’s npm and GitHub accounts. OpenAI’s GitHub Actions workflow downloaded and ran the malicious package, which had access to macOS code-signing certificates and notarization materials. OpenAI is revoking and rotating these certificates and requiring macOS users to update apps by May 8, 2026, to prevent potential misuse of the old certificates. This incident shows that even trusted developer workflows can become vectors for supply-chain attacks, putting code-signing credentials at risk. The risk persists because attackers could use stolen certificates to sign malicious macOS apps that appear legitimate, undermining software trust and distribution integrity.

Part of the PlainSec briefing for 2026-04-13

Editions

Sources