3 Sources
[1]
OpenAI flags software supply chain scare
Why it matters: The incident could have allowed hackers to exfiltrate a certificate that could make phony OpenAI apps look legitimate -- although OpenAI says it hasn't seen this happen. * Google has also linked the broader hacking campaign to a North Korean hacker group. Zoom in: OpenAI said in a
[2]
OpenAI apps for MacOS exposed by threat
A wider ranging security incident reported by Google Threat Intelligence Group last week prompted OpenAI to take action around its certification process. Open AI said on Friday (10 April) that it would be working on safeguarding and updating the certification process for its apps running on MacOS
[3]
OpenAI Reveals Security Breach, Tightens macOS App Verification Protocols
On Friday, the OpenAI said it uncovered a security problem tied to Axios, a third-party developer library, and moved to tighten the way its macOS apps are verified so impostor software can't masquerade as official releases. Reuters reported that OpenAI said it did not find signs that customer
Share
Copy Link
OpenAI disclosed a security incident on March 31 involving a compromised third-party developer library that could have enabled hackers to create fake OpenAI apps. The company is now revoking certificates and requiring Mac users to update ChatGPT, Atlas, and Codex by May 8. Google Threat Intelligence linked the broader campaign to North Korean hackers, though OpenAI found no evidence of user data compromise.
OpenAI disclosed a security incident on Friday that exposed its macOS apps to a potential software supply chain attack, prompting the company to overhaul its security certification process and mandate immediate user updates
1
. The breach occurred on March 31 when a GitHub Actions workflow used to sign certificates for macOS applications downloaded a malicious update from the Axios developer library, a widely used JavaScript library for making HTTP requests that is unaffiliated with Axios Media1
. Hackers who hijacked a developer's account published two infected updates to the Axios library before detection, creating a vulnerability that could have allowed attackers to exfiltrate certificates and create fake OpenAI apps that would appear legitimate to devices and the App Store1
.
Source: Benzinga
Google Threat Intelligence Group connected the wider hacking campaign to a North Korean hacker group, underscoring how AI companies have become prime targets for classic software supply chain attacks alongside novel AI-specific threats
1
2
. The compromise affected the company's GitHub workflow, which could reach signing certificates and notarization materials used to authenticate macOS versions of ChatGPT, Codex, and Atlas3
. Despite the severity of the vulnerability, OpenAI emphasized that there was no evidence any user data, intellectual property, or internal systems were compromised, and no signs that iOS, Android, Windows, or other platforms' apps were affected1
2
.
Source: Silicon Republic
In response to the security incident, OpenAI is implementing stringent macOS app verification protocols and revoking existing security certifications out of an abundance of caution
2
. The company will stop supporting older versions of its macOS apps on May 8, giving users a 30-day window to update before the revoked certificate could block new downloads and first-time launches1
. Mac users of ChatGPT, Codex, and Atlas are required to upgrade to the newest versions to ensure compliance with new security protocols, as older versions will no longer receive updates or support and may become non-functional2
. The root cause was identified as a misconfiguration in the GitHub Actions workflow, which has since been addressed2
.Related Stories
The incident highlights the escalating cybersecurity challenges facing AI companies as they become high-value targets for state-sponsored actors and sophisticated threat groups. OpenAI confirmed that user passwords and OpenAI API keys were unaffected by the potential breach, and no evidence of malware signed as OpenAI had been detected
2
. The company is reportedly finalizing a model with enhanced cybersecurity features through its Trusted Access for Cyber program, which it plans to deploy to a select group of companies, reflecting its commitment to addressing security concerns alongside its growth trajectory3
. This proactive approach to macOS app verification effectively turns patching into a gatekeeper for app legitimacy, aiming to reduce the odds that forged builds can circulate with credible-looking signing3
. The timing is particularly significant as OpenAI navigates broader scrutiny and competition in the AI sector, with the company framing the move as a preventative step rather than a response to confirmed user data theft3
.Summarized by
Navi
[2]
27 Nov 2025•Technology

27 Jul 2026•Technology

12 May 2026•Technology

1
Technology

2
Technology

3
Science and Research
