Vulnerabilities · 154 days ago
OpenAI’s macOS app-signing process executed a malicious Axios package version 1.14.1 during a supply-chain attack linked to North Korean group UNC1069, exposing code-signing certificates used for ChatGPT Desktop, Codex, and other apps. The company found no evidence that user data, systems, or software were compromised, but the incident breaks the assumption that CI workflows are safe from supply-chain malware execution.
The Axios compromise involved malicious versions live for about three hours after attackers hijacked the maintainer’s npm and GitHub accounts. OpenAI’s GitHub Actions workflow downloaded and ran the malicious package, which had access to macOS code-signing certificates and notarization materials. OpenAI is revoking and rotating these certificates and requiring macOS users to update apps by May 8, 2026, to prevent potential misuse of the old certificates.
This incident shows that even trusted developer workflows can become vectors for supply-chain attacks, putting code-signing credentials at risk. The risk persists because attackers could use stolen certificates to sign malicious macOS apps that appear legitimate, undermining software trust and distribution integrity.
5 sources covering this story
OpenAI's Mac apps need updates thanks to the Axios hack
The company said a developer tool automatically retrieved a malicious version of the popular open-source library, but insists the integrity of its systems and software were not impacted.
OpenAI rotates macOS certs after Axios attack hit code-signing workflow
OpenAI is rotating potentially exposed macOS code-signing certificates after a GitHub Actions workflow executed a malicious Axios package during a recent supply chain attack.
OpenAI Impacted by North Korea-Linked Axios Supply Chain Hack
The AI giant is taking action after determining that a macOS code signing certificate may have been compromised.
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident
OpenAI revoked its macOS signing certificate after a malicious Axios dependency incident on March 31, 2026, preventing potential software misuse.
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipel...
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.
Part of the PlainSec briefing for 2026-04-13