logo

OpenAI Warns macOS Users to Update ChatGPT and Codex Immediately

ID: d7bd7d1c-382e-5c19-8aa7-7357c712709a

STIX ID: report--d7bd7d1c-382e-5c19-8aa7-7357c712709a

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-11

Date Updated: 2026-04-21

Author: Guru Baran

...
...

OpenAI disclosed that on March 31, 2026, threat actors likely linked to North Korea compromised an Axios maintainer's npm account and published malicious versions (v1.14.1 and v0.30.4) that added a hidden dependency, `plain-crypto-js`, functioning as a cross-platform RAT; the malicious package was pulled into OpenAI's GitHub Actions build pipeline and gained access to macOS code-signing and notarization materials. OpenAI reported no evidence of user data, API key compromise, or system tampering, but revoked and rotated macOS certificates, required macOS app updates, and remediated the CI misconfiguration; the incident highlights the severe risks of software supply-chain attacks and recommends dependency pinning, integrity verification, and workflow audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.