CSIDB logo
Incident

OpenAI

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-08-13 01:13

Linked entities

Victim
OpenAI
Threat actors
2 actors
Sources
4 sources

Timeline

Occurred
Mar 2026
Discovered
Apr 2026
Disclosed
Apr 2026
Resolved
May 2026

Summary

OpenAI discovered that a GitHub Actions workflow used to sign its macOS applications downloaded a compromised version of a widely used JavaScript library, which could have exposed its code-signing certificate. Investigation found no evidence that user data, internal systems, or intellectual property were accessed, but the company revoked and rotated the certificate to prevent potential misuse. As a result, older versions of its macOS desktop apps will no longer be supported or functional unless users update to newer versions signed with the new certificate.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

OpenAI disclosed on Friday, April 10 2026, that it was among the organizations affected by a North Korea‑linked supply chain compromise of the Axios npm package, in which attackers hijacked the maintainer’s account and published malicious versions 1.14.1 and 0.30.4 containing a dependency called plain‑crypto-js that deployed the cross‑platform WAVESHAPER.V2 backdoor. The malicious packages were available for only a few hours before being detected and removed, but OpenAI’s GitHub Actions workflow used in its macOS app‑signing process downloaded and executed the tainted Axios version 1.14.1 on March 31. This workflow had access to the certificate and notarization material used to sign OpenAI’s macOS applications, including ChatGPT Desktop, Codex, Codex‑cli and Atlas. OpenAI’s internal analysis concluded that the signing certificate present in the workflow was not successfully exfiltrated by the malicious payload due to the timing of execution, certificate injection into the job, job sequencing and other mitigating factors, and found no evidence that user data, internal systems or intellectual property were compromised or that its software was altered. The company also confirmed that passwords and OpenAI API keys were not affected by the incident.

In response, OpenAI revoked and rotated the macOS signing certificate as a precaution, halted new notarizations using the old certificate and announced that the certificate would be fully revoked on May 8 2026, after which macOS security protections will block new downloads and first‑time launches of any apps signed with the previous certificate. To minimize disruption, OpenAI provided a 30‑day window before the revocation to allow users to update to the latest versions of its macOS apps, which are being re‑signed with the new certificate; the earliest releases bearing the updated certificate are ChatGPT Desktop 1.2026.071, Codex App 26.406.40811, Codex CLI 0.119.0 and Atlas 1.2026.84.2. OpenAI stated that older versions of its macOS desktop apps will no longer receive updates or support starting May 8 2026 and may become non‑functional, and that it is working with Apple to ensure that software signed with the old certificate cannot be newly notarized. The company also addressed the root cause—a misconfiguration in the GitHub Actions workflow—and updated its security certifications to require all macOS users to run the latest versions of its applications.

OpenAI noted that the Axios compromise was one of two major supply chain attacks observed in March 2026, the other targeting the Trivy vulnerability scanner and attributed to the threat group TeamPCP (also tracked as UNC6780). The Axios incident was linked by the Google Threat Intelligence Group to the North Korean hacking group UNC1069, which is primarily known for cryptocurrency theft and financially motivated operations. OpenAI’s blog post and subsequent statements emphasized that, while the access gained via the malicious Axios package could have been used for espionage, there was no indication that the attackers succeeded in exfiltrating the signing certificate or otherwise abused the access obtained through the compromised workflow.

Sources

Sources available to members: 4 sources.

CSIDB