logo

OpenAI Rotates macOS Certificates Following Axios Supply Chain Breach

ID: 2f2647fe-620c-5d2c-a0c5-0dddd06631e0

STIX ID: report--2f2647fe-620c-5d2c-a0c5-0dddd06631e0

Feed Name: HackRead

Threat Score
88/100

Date Published: 2026-04-13

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

OpenAI rotated macOS code-signing certificates after its build pipeline briefly fetched malicious Axios releases (including 1.14.1 and 0.30.4) that contained the WAVESHAPER.V2 backdoor hidden in a fake dependency (plain-crypto-js); the compromised packages were published following a hijack of the Axios lead developer account and executed within minutes of publication. The attack, attributed to North Korea-linked UNC1069, potentially exposed signing credentials used for ChatGPT Desktop, Codex, Codex CLI and Atlas, prompting OpenAI to revoke certificates, publish re-signed app versions (Atlas: 1.2026.84.2, Codex CLI: 0.119.0, Codex App: 26.406.40811, ChatGPT Desktop: 1.2026.071) and require updates before macOS begins blocking the old signatures on 8 May 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.