logo

OpenAI Warns Mac Users to Update Apps After Supply-Chain Attack

ID: ac3895c3-a7f0-58c2-b4a8-58b25a3a3d22

STIX ID: report--ac3895c3-a7f0-58c2-b4a8-58b25a3a3d22

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2026-05-15

Date Updated: 2026-05-16

Author: Joseph Ofonagoro

...
...

OpenAI disclosed a supply-chain compromise in which malware from the Mini Shai-Hulud campaign, delivered via a popular npm package, infected two developer machines and exposed developer credentials and code-signing certificates for its macOS, iOS, and Windows apps; the company found no evidence of customer-data access, rotated certificates, engaged external forensics, and is urging macOS users to install specific updated app versions by June 12.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.