OpenAI said a malicious axios npm package was executed through one of its GitHub Actions workflows as part of a broader software supply chain attack linked to North Korean actors, exposing a code-signing workflow used for macOS applications including ChatGPT Desktop, Codex, Codex CLI, and Atlas. The company said the affected workflow had access to certificate and notarization material, but its investigation found no evidence that signing certificates were successfully exfiltrated or abused, and no signs that user data, passwords, API keys, internal systems, intellectual property, web services, or non-macOS platforms were compromised.
In response, OpenAI said it fixed the GitHub Actions misconfiguration, is revoking and rotating its macOS code-signing certificates, and is requiring users to update to newly signed versions of its macOS apps. The company warned that older macOS app versions will lose updates and support and may stop working after May 8, when the previous certificate is fully revoked; the underlying axios compromise has been tied to a campaign in which attackers reportedly used social engineering against an npm maintainer to publish malicious packages that deployed a cross-platform remote access trojan.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
OpenAI announced that effective May 8, 2026, older versions of its macOS desktop apps signed with the previous certificate will no longer be supported, may stop receiving updates, and could stop functioning once the old certificate is fully revoked.
OpenAI disclosed that it was revoking and rotating macOS code-signing certificates and updating security configurations after the incident, including fixing the GitHub Actions misconfiguration. It required macOS users to install newly signed versions of affected applications.
Following the workflow compromise, OpenAI investigated and said it found no evidence that its macOS signing certificates were stolen or abused. The company also stated that user data, accounts, passwords, API keys, internal systems, intellectual property, web services, and non-macOS platforms were not impacted.
On March 31, 2026, a compromised Axios npm package was downloaded and run through an OpenAI GitHub Actions workflow as part of a broader software supply chain attack. The workflow had access to certificate and notarization material used to sign OpenAI macOS applications including ChatGPT Desktop, Codex, Codex CLI, and Atlas.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.