{"id":12061,"date":"2026-04-12T10:03:31","date_gmt":"2026-04-12T10:03:31","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/12\/openai-warns-macos-users-to-update-chatgpt-and-codex-immediately\/"},"modified":"2026-04-12T10:03:31","modified_gmt":"2026-04-12T10:03:31","slug":"openai-warns-macos-users-to-update-chatgpt-and-codex-immediately","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/12\/openai-warns-macos-users-to-update-chatgpt-and-codex-immediately\/","title":{"rendered":"OpenAI Warns macOS Users to Update ChatGPT and Codex Immediately"},"content":{"rendered":"<p>    OpenAI Warns macOS Users to Update ChatGPT and Codex Immediately<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>OpenAI has disclosed a security incident tied to the compromise of Axios, a widely used third-party JavaScript developer library, as part of a broader software <a href=\"https:\/\/cybersecuritynews.com\/axios-npm-packages-compromised\/\" target=\"_blank\" rel=\"noreferrer noopener\">supply chain attack detected on March 31, 2026<\/a>.<\/p>\n<p>While the company confirmed no user data, API keys, or systems were compromised, it is taking aggressive precautionary measures to protect its macOS application certification infrastructure.<\/p>\n<p>On March 31, 2026 (UTC), threat actors believed to be linked to North Korea hijacked the npm account of an Axios library maintainer and pushed malicious updates, specifically versions v1.14.1 and v0.30.4.<\/p>\n<p>These compromised versions silently introduced a hidden dependency called <code>plain-crypto-js<\/code>, which functioned as a cross-platform Remote Access Trojan (RAT) capable of targeting Windows, macOS, and Linux environments.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/hackers-use-poisoned-axios-package-and-phantom-dependency\/\" target=\"_blank\" rel=\"noreferrer noopener\">According to Palo Alto Networks\u2019 Unit 42<\/a>, the malware was engineered to perform system reconnaissance, establish persistence, and then self-destruct to evade forensic detection.<\/p>\n<p>Axios is one of the most widely downloaded JavaScript libraries, with over 100 million weekly downloads, making the blast radius of this supply chain attack particularly significant.<\/p>\n<h2 class=\"wp-block-heading\" id=\"how-openai-was-affected\"><strong>OpenAI\u2019s Incident Response<\/strong><\/h2>\n<p>OpenAI\u2019s internal build pipeline leveraged Axios as part of its GitHub Actions workflow. When the workflow automatically pulled the now-malicious Axios update, the compromised library gained access to certificate and notarization material used to digitally sign OpenAI\u2019s macOS applications, including ChatGPT Desktop, Codex, and Atlas.<\/p>\n<p>This type of access is critical: code-signing certificates are the trust anchors that verify to Apple\u2019s systems and the App Store that an application is genuinely from its claimed publisher.<\/p>\n<p>Had an attacker exploited this access, they could theoretically have fabricated counterfeit OpenAI applications carrying a legitimate certificate, deceiving both end-user devices and the App Store into treating them as authentic. OpenAI confirmed the root cause was a misconfiguration in its GitHub Actions workflow, which has since been remediated.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">We recently identified a security issue involving the third-party developer library Axios that was part of a broader industry incident. We found no evidence that OpenAI user data was accessed, that our systems were compromised, or that our software was altered.<\/p>\n<p>Out of an\u2026<\/p>\n<p>\u2014 OpenAI (@OpenAI) <a href=\"https:\/\/twitter.com\/OpenAI\/status\/2042780052669239782?ref_src=twsrc%5Etfw\">April 11, 2026<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/div>\n<\/figure>\n<p>OpenAI has moved quickly to contain the potential fallout. The company is revoking and rotating all <a href=\"https:\/\/cybersecuritynews.com\/clickfix-abuses-legitimate-homebrew-workflow\/\" target=\"_blank\" rel=\"noreferrer noopener\">macOS security certificates<\/a> to invalidate any trust material that may have been exposed during the incident.<\/p>\n<p>All macOS users are now required to update their OpenAI applications ChatGPT, Codex, Atlas, and Codex CLI to the latest versions to receive the refreshed certificates. OpenAI emphasized that users do not need to change passwords, as passwords and API keys were entirely unaffected by this incident.<\/p>\n<p>Critically, after May 8, 2026, older versions of these macOS applications will cease to receive updates and support, and may become fully non-functional. Users can update safely via an in-app update prompt or through official download links provided by OpenAI.<\/p>\n<p>The attack\u2019s impact on OpenAI was confined exclusively to macOS applications. Applications on Android, Linux, and Windows platforms were not affected. OpenAI reiterated that it found no evidence of user data exfiltration, system compromise, or software tampering.<\/p>\n<p>This incident underscores the growing threat of software supply chain attacks targeting developer tooling, a vector increasingly favored by sophisticated state-linked threat actors.<\/p>\n<p>Organizations relying on open-source libraries via automated <a href=\"https:\/\/cybersecuritynews.com\/ci-cd-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">CI\/CD pipelines<\/a> should implement dependency pinning, integrity verification, and workflow audits as standard security hygiene to reduce exposure to similar incidents.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/openai-macos-users\/\">OpenAI Warns macOS Users to Update ChatGPT and Codex Immediately<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/openai-macos-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>OpenAI Warns macOS Users to Update ChatGPT and Codex Immediately OpenAI has disclosed a security incident tied to the compromise of Axios, a widely used third-party JavaScript developer library, as part of a broader software supply chain attack detected on March 31, 2026. While the company confirmed no user data, API keys, or systems were [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-12061","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12061"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12061"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12061\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12061"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12061"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12061"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}