AI Privacy IncidentMarch 31, 2026

OpenAI macOS signing pipeline compromise via Axios supply chain

Vendor: OpenAI
Product: ChatGPT Desktop, Codex, Atlas (macOS)
Severity: high
Status: confirmed-resolved
Users affected: all macOS users of ChatGPT Desktop, Codex, and Atlas; older builds stopped functioning after 2026-05-08

Summary

On March 31, 2026, OpenAI's GitHub Actions workflow for notarizing macOS applications executed a malicious version of the Axios JavaScript library during a supply chain campaign that Socket attributed to North Korean actors. The compromised pipeline held code-signing certificates for ChatGPT Desktop, Codex, and Atlas. OpenAI disclosed the incident on April 11, 2026, revoked the affected certificates, rebuilt the macOS applications, and coordinated with Apple to block notarization attempts using the previous certificate. The company stated it found no evidence that user data or production software were compromised.

What happened

  • A malicious version of Axios (1.14.1) executed inside OpenAI's GitHub Actions workflow on March 31, 2026, during a supply chain campaign tracked by Socket.
  • The workflow was the one OpenAI used to notarize macOS applications and held code-signing certificates for ChatGPT Desktop, Codex, and Atlas.
  • OpenAI rotated the affected certificates, rebuilt the macOS applications with new credentials, and worked with Apple to block notarization using the previous certificate.
  • Users were required to update; older builds signed with the rotated certificate stopped functioning after May 8, 2026.
  • Socket published its writeup on April 11, 2026. Developer reaction was mixed on timing and scope.

Timeline

  • 2026-03-31 - Malicious Axios package executes in OpenAI's macOS signing workflow.
  • 2026-04-11 - OpenAI publishes disclosure; Socket publishes research writeup.
  • 2026-05-08 - Older builds signed with the rotated certificate stop functioning.

What the vendor has confirmed

OpenAI described the root cause as "a misconfiguration in the GitHub Actions workflow" that pinned Axios to a floating tag rather than a specific commit hash and did not enforce version-age validation. The company said the signing certificates for the three macOS applications were treated as potentially compromised and were rotated, and that Apple assisted in blocking notarization attempts using the previous certificate. OpenAI said it found "no evidence that user data, internal systems, or production software were compromised."

Broader context

A signed desktop AI client inherits the security posture of every dependency its vendor's build pipeline pulls in. The failure mode at play here - a floating package reference resolving to a newly published malicious version during a CI run with privileged credentials - is not specific to AI products, but it carries higher stakes when the compromised output is the signing material for software that handles personal or business-sensitive files on an end user's machine.

Sources

Selvam Sivakumar
Written by

Selvam Sivakumar

Founder, Elephas.app

Selvam Sivakumar is the founder of Elephas and an expert in AI, Mac apps, and productivity tools. He writes about practical ways professionals can use AI to work smarter while keeping their data private.

Related Resources

news

The Open Weights Fight: What NVIDIA, Anthropic, and Meta Are Really Arguing About

133 companies signed a letter defending open weight AI models. Anthropic pushed back. Zuckerberg made a third argument. Here is what each side really wants, and the one party none of them argues about.

15 min read
news

Claude Shared Chats and Google: The Explanation Has a Gap

Claude shared chats and Google search: the robots.txt explanation everyone repeated lists a bare URL, not a readable chat. What we checked on 27 July 2026.

13 min read
news

Apple Sues OpenAI: The Lawsuit Everyone Thought Would Go the Other Way

Apple filed a trade-secret lawsuit against OpenAI on July 10, 2026, naming hardware chief Tang Tan and engineer Chang Liu. Two months earlier OpenAI was the one weighing a case against Apple, and never filed. What the complaint alleges, how OpenAI responded, and the Musk-Altman fallout.

9 min read
news

ToqanClaw Brings Private AI to 5 Million Businesses

Prosus launched ToqanClaw, a private AI for five million businesses. Here is how Elephas gives Mac and iPhone users the same private AI assistant, with on-device redaction.

9 min read