Close Menu
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
What's Hot

Bitcoin, Ethereum Surge As $430M Short Squeeze Fuels Rally

April 15, 2026

Eigen Labs Launches Project Darkbloom to Turn Idle Macs Into AI Compute Network

April 15, 2026

Is XRP Actually ISO20022 Compliant? A Legal Expert Just Changed the Conversation

April 15, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
CatchTheBullCatchTheBull
Blockchain

OpenAI Rotates macOS Certificates After Axios Supply Chain Attack

By WebDeskApril 15, 20263 Mins Read
OpenAI Rotates macOS Certificates After Axios Supply Chain Attack
Share
Facebook Twitter LinkedIn Pinterest Email


Iris Coleman
Apr 15, 2026 02:02

OpenAI responds to North Korea-linked Axios npm compromise by rotating code signing certificates. macOS users must update ChatGPT, Codex apps by May 8.





OpenAI is forcing all macOS users to update their desktop applications after the company’s app-signing workflow was exposed to the Axios supply chain attack—a compromise attributed to North Korean threat actors that hit the popular JavaScript library on March 31, 2026.

The AI giant says it found no evidence that user data was accessed or that its software was tampered with. But the company isn’t taking chances: it’s treating its macOS code signing certificate as compromised and revoking it entirely on May 8, 2026.

What Actually Happened

When the compromised Axios version 1.14.1 hit npm on March 31, a GitHub Actions workflow OpenAI uses for macOS app signing downloaded and executed the malicious code. That workflow had access to certificates used to sign ChatGPT Desktop, Codex, Codex CLI, and Atlas—the credentials that tell macOS “yes, this software really comes from OpenAI.”

The root cause? A misconfiguration. OpenAI’s workflow referenced Axios using a floating tag rather than a pinned commit hash, and lacked a configured minimumReleaseAge for new packages. Classic supply chain vulnerability.

OpenAI’s internal analysis suggests the signing certificate likely wasn’t successfully exfiltrated due to timing and execution sequencing. But “likely” isn’t good enough when you’re signing software that runs on millions of machines.

The Broader Attack

The Axios compromise wasn’t targeting OpenAI specifically. Security researchers, including Google’s threat intelligence team, have linked the attack to a North Korea-nexus actor—possibly Sapphire Sleet or UNC1069. The attackers compromised an npm maintainer’s account and injected a malicious dependency called ‘plain-crypto-js’ that deployed a cross-platform RAT capable of reconnaissance, persistence, and self-destruction to avoid detection.

The attack hit organizations across business services, financial services, and tech sectors globally.

What Users Need to Do

If you run any OpenAI macOS apps, update now. After May 8, older versions will stop functioning entirely. Minimum required versions:

  • ChatGPT Desktop: 1.2026.051
  • Codex App: 26.406.40811
  • Codex CLI: 0.119.0
  • Atlas: 1.2026.84.2

Download only from official sources or via in-app updates. OpenAI explicitly warns against installing anything from emails, ads, or third-party sites—sound advice given that a malicious actor with the old certificate could theoretically sign fake apps that look legitimate.

Windows, iOS, Android, and Linux users aren’t affected. Neither are web versions. Passwords and API keys remain secure.

Why the 30-Day Window?

OpenAI could revoke the certificate immediately but chose not to. New notarization with the compromised certificate is already blocked, meaning any fraudulent app signed with it would fail macOS’s default security checks unless users manually override them.

The delay gives users time to update through normal channels rather than waking up to broken software. OpenAI says it’s monitoring for any signs of certificate misuse and will accelerate revocation if malicious activity appears.

The incident underscores how supply chain attacks continue to ripple through the software ecosystem. One compromised npm package, and suddenly OpenAI is rotating certificates across its entire macOS product line. For developers, the lesson is clear: pin your dependencies to specific commits, not floating tags.

Image source: Shutterstock


Credit: Source link

Previous ArticleGrayscale Signals $2.2T Crypto Inflow Potential as $110T Wealth Transfer Accelerates Allocation Shift – Featured Bitcoin News
Next Article Bitcoin Price Cools Off, Bulls Prepare for Next Leg Higher

Related Posts

Eigen Labs Launches Project Darkbloom to Turn Idle Macs Into AI Compute Network

April 15, 2026

Paxos Labs Secures $12M for Crypto Yield Platform Amplify

April 14, 2026

Harvey AI Processes 700K Daily Legal Tasks as Agentic AI Reshapes Law

April 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Bitcoin, Ethereum Surge As $430M Short Squeeze Fuels Rally

April 15, 2026

Eigen Labs Launches Project Darkbloom to Turn Idle Macs Into AI Compute Network

April 15, 2026

Is XRP Actually ISO20022 Compliant? A Legal Expert Just Changed the Conversation

April 15, 2026

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

Advertisement Banner

Welcome to CatchTheBull, your trusted source for the latest Crypto News and Airdrops. We bring you real-time updates, expert insights, and opportunities to stay ahead in the crypto world. Discover trending projects, market analyses, and airdrop details all in one place.

Join us on this journey to navigate the ever-evolving blockchain universe!

Facebook X (Twitter) Instagram YouTube
Top Insights

Ethereum Sees Spike In Daily Transactions While Price Momentum Gradually Fades

Spartans Casino Aims to Scale Past Pulsz & Global Poker by the End of 2026

Harvey AI Processes 700K Daily Legal Tasks as Agentic AI Reshapes Law

Get Informed

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

© 2026 CatchTheBull. All Rights Are Reserved.
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$73,726.00-1.30%
  • ethereumEthereum(ETH)$2,314.77-2.81%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$612.62-0.44%
  • rippleXRP(XRP)$1.35-1.49%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$82.81-3.82%
  • tronTRON(TRX)$0.3233280.71%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.08%
  • dogecoinDogecoin(DOGE)$0.092910-0.65%
  • whitebitWhiteBIT Coin(WBT)$54.11-1.55%
  • USDSUSDS(USDS)$1.000.00%
  • HyperliquidHyperliquid(HYPE)$43.40-2.66%
  • leo-tokenLEO Token(LEO)$10.130.34%
  • cardanoCardano(ADA)$0.238972-2.29%
  • bitcoin-cashBitcoin Cash(BCH)$431.06-1.26%
  • chainlinkChainlink(LINK)$9.02-2.22%
  • moneroMonero(XMR)$340.58-2.17%
  • zcashZcash(ZEC)$351.71-4.14%
  • Ethena USDeEthena USDe(USDE)$1.00-0.01%
  • CantonCanton(CC)$0.149976-3.76%
  • stellarStellar(XLM)$0.155302-0.10%
  • MemeCoreMemeCore(M)$2.861.83%
  • daiDai(DAI)$1.000.00%
  • litecoinLitecoin(LTC)$53.99-0.64%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.01%
  • USD1USD1(USD1)$1.000.03%
  • avalanche-2Avalanche(AVAX)$9.30-1.26%
  • RainRain(RAIN)$0.007808-3.39%
  • hedera-hashgraphHedera(HBAR)$0.085207-1.52%
  • suiSui(SUI)$0.93-1.72%
  • RaveDAORaveDAO(RAVE)$14.2226.15%
  • shiba-inuShiba Inu(SHIB)$0.000006-1.04%
  • the-open-networkToncoin(TON)$1.37-4.68%
  • crypto-com-chainCronos(CRO)$0.068574-2.71%
  • Circle USYCCircle USYC(USYC)$1.120.00%
  • tether-goldTether Gold(XAUT)$4,787.310.79%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.0804920.24%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • pax-goldPAX Gold(PAXG)$4,802.550.90%
  • BittensorBittensor(TAO)$244.05-3.36%
  • Global DollarGlobal Dollar(USDG)$1.00-0.02%
  • mantleMantle(MNT)$0.65-4.87%
  • uniswapUniswap(UNI)$3.13-1.45%
  • polkadotPolkadot(DOT)$1.15-3.27%
  • Falcon USDFalcon USD(USDF)$1.000.03%
  • okbOKB(OKB)$84.31-0.69%
  • nearNEAR Protocol(NEAR)$1.35-5.51%
  • SkySky(SKY)$0.0743090.65%
  • Pi NetworkPi Network(PI)$0.1669561.43%