Response to the Axios Development Tool Compromise Incident
Key point
Due to the impact of the Axios supply chain attack, OpenAI is replacing its macOS signing certificates.
Details
On March 31, 2026 (UTC), the widely used third-party library Axios 1.14.1 was compromised as part of a larger software supply chain attack, and OpenAI disclosed that a GitHub Actions workflow used in its macOS app signing process downloaded and executed this malicious version.
The affected workflow had access to certificates and notarization materials used to sign ChatGPT Desktop, Codex, Codex-cli, and Atlas. However, OpenAI assessed that due to several mitigating factors—including timing, the point at which certificate injection occurred, and job sequencing—it is unlikely that the certificates were actually exfiltrated. Nevertheless, out of an abundance of caution, OpenAI is treating the certificates as compromised and is proceeding with revocation and replacement.
OpenAI stated that, to date, there is no evidence of access to OpenAI user data, system compromise, intellectual property exfiltration, or software tampering. It also confirmed that no tampering of existing installations or unexpected notarization has been found, and clarified that iOS, Android, Linux, Windows, and web versions are not affected.
As response measures, the following steps are underway:
- Replacing macOS code signing certificates and distributing new builds
- Working with Apple to block new notarization using the previous certificates
- Engaging an external digital forensics/IR firm
- Fixing the root cause in the GitHub Actions workflow
Additionally, new downloads and execution of apps signed with the previous certificates may be blocked by macOS security policy, and starting May 8, 2026, older macOS apps will no longer be eligible for updates or support and may not function properly. The earliest releases unaffected by this are ChatGPT Desktop 1.2026.051, Codex App 26.406.40811, Codex CLI 0.119.0, and Atlas 1.2026.84.2.
OpenAI recommends that users update to the latest version via in-app updates or the official download page, and emphasized that unofficial installers from emails, messages, ads, or third-party sites should not be used.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.