Back to stories
Industry

OpenAI to Revoke macOS App Certificate on May 8 After Axios Supply Chain Attack

Michael Ouroumis3 min read
OpenAI to Revoke macOS App Certificate on May 8 After Axios Supply Chain Attack

OpenAI has told macOS users they have until May 8, 2026 to update its desktop applications, after the company decided to revoke the Apple developer certificate used to sign ChatGPT Desktop, Codex, Codex CLI and the Atlas browser. The disclosure, published in an OpenAI blog post on April 10, follows a software supply chain attack against the popular Axios JavaScript HTTP client that briefly threaded malicious code through OpenAI's macOS build pipeline on March 31.

What happened

According to OpenAI's disclosure and reporting from The Hacker News, attackers published tampered Axios releases (versions 1.14.1 and 0.30.4) that pulled in a hidden dependency called "plain-crypto-js." That dependency dropped a cross-platform backdoor researchers have tracked as WAVESHAPER.V2, capable of running on Windows, macOS and Linux. A GitHub Actions workflow OpenAI uses to sign and notarize its Mac apps fetched and executed one of those poisoned Axios builds during a routine job.

The job had access to the Apple Developer ID certificate used to code-sign the company's desktop products. OpenAI's investigation concluded the certificate was "likely not" successfully exfiltrated, citing the timing of the malicious payload, when the certificate was injected into the job, and other mitigating factors. Even so, the company is rotating signing material and asking every user to move to a freshly signed build.

What OpenAI is saying

In its public response, OpenAI wrote that it "found no evidence that OpenAI user data was accessed, that our systems or intellectual property were compromised, or that our software was altered." The company framed the certificate revocation as a precaution rather than a confirmed breach, but said older app versions will be blocked by macOS security protections once the certificate is invalidated on May 8.

What users need to do

OpenAI has published the minimum builds users must run after the revocation:

Apps left unpatched after the deadline will not auto-update and may simply refuse to launch, since macOS Gatekeeper will reject the revoked signature. Enterprise customers who manage OpenAI binaries through MDM tooling will need to push the new versions before the cutoff.

Why it matters

The incident is a reminder that AI vendors inherit the same open-source supply chain risk as any other software company. Axios is one of the most-downloaded packages on npm — over 70 million weekly downloads — and a single compromised maintenance release was enough to inject a remote-access trojan into the build pipeline of the largest consumer AI app on the planet. The broader attack chain — system reconnaissance and persistence from WAVESHAPER.V2, paired with cleanup routines in the dropper that delete the malicious payload after execution — is explicitly aimed at evading the kind of after-the-fact forensics OpenAI has now had to perform.

For security teams, the practical takeaway is narrower: treat the May 8 deadline as a hard inventory date for any Mac running OpenAI's desktop tooling, and verify that CI/CD pipelines that touch signing material are not pulling third-party dependencies on a floating tag.

Learn AI for Free — FreeAcademy.ai

Take "AI for Business: Practical Implementation" — a free course with certificate to master the skills behind this story.

More in Industry

Netomi Raises $110M Series C as Accenture and Adobe Bet on Agentic Customer Service
Industry

Netomi Raises $110M Series C as Accenture and Adobe Bet on Agentic Customer Service

Netomi closed a $110 million Series C led by Accenture Ventures with Adobe Ventures and WndrCo, pairing the round with a global alliance to deploy agentic AI customer experiences inside Fortune 500 contact centers.

4 min ago2 min read
Apple Reports Q2 2026 Earnings With AI Strategy In Focus As Capex Lags Big Tech Peers
Industry

Apple Reports Q2 2026 Earnings With AI Strategy In Focus As Capex Lags Big Tech Peers

Apple posts fiscal Q2 2026 results today with Wall Street expecting ~$109.7B revenue, but the spotlight is on a thin AI capital plan as Tim Cook prepares to hand the CEO seat to John Ternus.

4 hours ago3 min read
Aidoc Raises $150M Series E Led by Goldman Sachs as Clinical AI Eyes IPO
Industry

Aidoc Raises $150M Series E Led by Goldman Sachs as Clinical AI Eyes IPO

Clinical AI provider Aidoc closed a $150 million Series E led by Goldman Sachs Alternatives to scale its CARE healthcare foundation model, lifting total funding past $500 million as the company prepares for a potential IPO.

6 hours ago3 min read