OpenAI has announced that all macOS users must update their desktop applications following a security incident related to Axios, a commonly used third-party developer library. The event was part of a larger software supply chain attack that was reported on March 31, 2026. In this incident, a GitHub Actions workflow utilized in OpenAI’s macOS app-signing process inadvertently downloaded and executed a malicious version of Axios. OpenAI has specified that this workflow had access to certificates necessary for signing macOS applications, including ChatGPT Desktop, Codex, Codex-cli, and Atlas.
Although OpenAI’s analysis suggests that the signing certificate was likely not compromised due to timing and other factors, the company is taking precautionary measures by treating the certificate as compromised, revoking it, and rotating it. OpenAI has assured that there is no evidence indicating any unauthorized access to user data, compromise of its systems or intellectual property, or tampering with its software. No instances of malware signed as OpenAI have been detected, and there has been no impact on passwords or API keys.
Commencing from May 8, 2026, older versions of the macOS apps will cease to receive updates or support and may become non-functional. Users are encouraged to update their applications through in-app notifications or official OpenAI download channels. The underlying cause of the issue was identified as a workflow misconfiguration related to a floating tag and the absence of a minimum release age for new packages. OpenAI has confirmed that this issue has been rectified. It is important to note that this incident does not impact the iOS, Android, Linux, Windows, or web versions of OpenAI applications.
