OpenAI revealed that it discovered a security incident with Axios, a third-party developer tool, and is now updating its security certifications.
The AI firm is now trying to mitigate any damage and ensure the proper certification of macOS applications is in place.
Currently, there is no evidence that any user data has been accessed in the incident, and intellectual property, systems, and software seem to not be compromised or altered.
All macOS users will be required to update their OpenAI apps to the latest versions to prevent risk of being distributed a fake OpenAI app, the company said.
Axios was compromised as part of a wider software supply chain attack carried out by threat actors thought to have links to North Korea on March 31.
The original attack led to the downloading and execution of a malicious version of Axios by OpenAI through a GitHub Actions workflow. The workflow involved certification of various macOS applications such as ChatGPT Desktop, Atlas, and Codex.
However, OpenAI said that its analysis showed that the signing certificate in the affected workflow was likely not exfiltrated by the malicious software.
Recommended reading
- The Biggest LLMs Are Generating Vulnerable Code by Default
- OpenAI Launches AI Safety Bug Bounty
- Microsoft Error Sees Confidential Emails Exposed to AI Tool Copilot
As of 8 May, versions of OpenAI macOS desktop apps that are older and not updated will not be able to receive supports or newer updates, and may stop functioning.
OpenAI did reiterate and assure users that API keys were not affected by the security issue, saying that the GitHub Actions workflow misconfiguration issue was addressed.





