OpenAI discloses supply chain attack targeting MacOS apps through compromised library

Reviewed byNidhi Govil

2 Sources

Share

OpenAI revealed a security breach on March 31 when hackers compromised the Axios JavaScript library, potentially exposing signing certificates for MacOS applications including ChatGPT. Google linked the attack to North Korean hackers. While no user data was compromised, OpenAI will mandate updates for Mac users and stop supporting older app versions by May 8.

OpenAI Flags Software Supply Chain Vulnerability

OpenAI disclosed a significant security breach on Friday that exposed its MacOS applications to a supply chain attack through a compromised third-party library. The incident unfolded on March 31 when a GitHub workflow used by the company to sign certificates for MacOS applications downloaded a malicious update from Axios, a widely used JavaScript library for making HTTP requests

1

. On the same day, hackers who had hijacked a developer's account published two infected updates to the Axios developer library before detection

1

. The Axios library involved in this breach is not affiliated with Axios Media.

Source: Benzinga

Source: Benzinga

MacOS App Verification Protocols Under Threat

The vulnerability could have allowed hackers to exfiltrate signing certificates for MacOS that would enable them to create phony OpenAI applications appearing legitimate to both devices and the App Store. OpenAI MacOS applications including ChatGPT, Atlas, and Codex were potentially affected by the compromise

1

. The GitHub workflow in question had access to certificate and notarization materials used to authenticate macOS apps, creating a serious cybersecurity risk

2

. However, OpenAI's internal investigation found that the workflow's signing certificate most likely remained intact despite the malicious attack

2

.

No Evidence of User Data Compromise Despite Breach

OpenAI emphasized there is no evidence of user data compromise, intellectual property theft, or internal systems penetration. The company confirmed that passwords and OpenAI API keys were not impacted by the breach

2

. OpenAI hasn't detected any signs that iOS, Android, Windows, or other platforms' apps have been affected, limiting the scope to MacOS environments

1

. Despite this reassurance, the incident highlights how AI companies have become prime targets for classic software supply chain attacks, not just novel AI-specific threats

1

.

Source: Axios

Source: Axios

North Korea Link and Broader Campaign Implications

Google has linked the broader hacking campaign to a North Korean hacker group, suggesting state-sponsored actors are actively targeting major technology firms

1

. OpenAI confirmed the compromise was part of a wider software supply-chain campaign that traces back to North Korea-linked actors

2

. This attribution raises concerns about the sophistication and persistence of threats facing companies developing cutting-edge artificial intelligence technologies.

Mandatory Updates and Strengthened Security Measures

As a precautionary measure, OpenAI will stop supporting older versions of its MacOS apps on May 8, giving users a 30-day window to update before the revoked certificate could block new downloads and first-time launches

1

. The company is updating its security credentials and requiring Mac users to upgrade to the latest application releases, effectively turning patching into a gatekeeper for app legitimacy

2

. Additionally, OpenAI is finalizing a model with enhanced cybersecurity features through its "Trusted Access for Cyber" program, which it plans to deploy to a select group of companies

2

. This incident underscores the critical importance of timely response and proactive security measures as OpenAI navigates both technical vulnerabilities and growing scrutiny around its partnerships and deployment of AI tools in sensitive environments.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo