OpenAI’s Mac apps need updates thanks to the Axios hack

OpenAI updated its security certificates and is requiring all macOS users to update to the latest versions after determining its products, along with many others, were impacted by a widespread supply-chain attack that briefly infected a popular open-source library in late March, the company said in a blog post Friday.

The artificial intelligence vendor said it “found no evidence that OpenAI user data was accessed, that our systems or intellectual property was compromised, or that our software was altered.”

Yet, because a GitHub workflow the company uses to sign certificates for macOS applications downloaded and executed a malicious version of Axios, the company is treating the soon-to-be defunct certificate as compromised.

A North Korean hacking group injected malware into two versions of Axios after it compromised the lead maintainer’s computer via social engineering and took over his npm and GitHub accounts. Jason Saayman, the lead maintainer for Axios, said the malicious versions of the software were live for about three hours before removal. 

Google Threat Intelligence Group, which tracks the threat group as UNC1069, said the impact of the attack was broad with ripple effects potentially exposing other popular packages. The JavaScript libraries flow into dependent downstream software through more than 100 million and 83 million downloads weekly. 

The attack was discovered just weeks after a series of other open-source tools, including Trivy, were compromised by UNC6780, also known as TeamPCP, resulting in aggressive extortion attempts. 

OpenAI insists the malware that infected Axios did not directly impact its certificate, which is designed to help customers confirm they are downloading legitimate software. 

“The signing certificate present in this workflow was likely not successfully exfiltrated by the malicious payload due to the timing of the payload execution, certificate injection into the job, sequencing of the job itself, and other mitigating factors,” the company said in the blog post. “Nevertheless, out of an abundance of caution we are treating the certificate as compromised, and are revoking and rotating it.”

Older versions of OpenAI’s macOS apps may lose functionality and will no longer be supported when the certificate is fully revoked May 8, the company said.

OpenAI, which hired a third-party digital forensics and incident response firm to aid its investigation and response, pinned the root cause of the security issue on a misconfiguration in its GitHub workflow. The company said it corrected that error and worked with Apple to ensure fraudulent apps posing as OpenAI cannot use the impacted certificate.

The 30-day window is designed to minimize disruption for users, but OpenAI said it will speed up the revocation deadline if it identifies any malicious activity. The company did not immediately respond to a request for comment.

Matt Kapko

Written by Matt Kapko

Matt Kapko is a reporter at CyberScoop. His beat includes cybercrime, ransomware, software defects and vulnerability (mis)management. The lifelong Californian started his journalism career in 2001 with previous stops at Cybersecurity Dive, CIO, SDxCentral and RCR Wireless News. Matt has a degree in journalism and history from Humboldt State University.

Source link

Visited 1 times, 1 visit(s) today

Related Article

Huawei Teases a Wider Foldable, and the Timing Feels Very Apple-Adjacent

Huawei’s new extra-wide foldable phone was revealed on Monday, and it’s already drawing comparisons to the next big thing from Apple. Little is known about the Pura X Max, teased on China’s Weibo social network, but the internet is buzzing over its uncommon proportions, wide aspect ratio and similarities with the rumored iPhone Fold expected to

New Self-Driving App, ‘Hey, Grok,’ and More

April 13, 2026 By Nehal Malik Tesla has just pulled the curtain back on its massive Spring 2026 update, and it is packed with features that fundamentally change how owners interact with their vehicles. From the long-awaited wake word for xAI’s Grok to a new self-driving app, this update is one of the most significant

Tesla launches Spring Update 2026 with ‘Hey Grok,’ new Self-Driving app, and more

Tesla is rolling out its Spring Update 2026 software, bringing over a dozen new features to its fleet. The highlights include a redesigned Self-Driving subscription app, voice-activated Grok, and a long-requested auto-install feature for software updates. The update also adds some fun touches, like a new “Cyberhog” Pet Mode character and custom virtual wraps for

Mobile Phone E Book Reader Market Analysis By Application, Type,

Mobile Phone E-Book Reader Market The Mobile Phone E Book Reader Market reached a valuation of 6.28 billion in 2025 and is anticipated to expand at a CAGR of 9.06% during the forecast period from 2026 to 2033, ultimately attaining an estimated value of 12.57 billion by 2033. Market growth is being driven by increasing

Apple removes old Pages, Keynote, Numbers apps for macOS

Apple has just made a change to its iWork lineup on the Mac, removing the old versions of Pages, Keynote, and Numbers from the App Store and leaving just the newer builds that support Apple Creator Studio. iWork apps now only available in Creator Studio versions on the Mac Earlier this year, Apple Creator Studio

Vivo X300 Ultra Gets Global Release Date

Summary created by Smart Answers AI In summary: Tech Advisor reports that the Vivo X300 Ultra is expected to launch globally on April 24, according to the Spanish Oppo store. Early buyers may receive €600 worth of gifts including a SmallRig Pro video stabilizer and case, plus a 10% subscriber discount. Availability in key markets

Elektros flags 12% rise in U.S. used EV sales

Elektros (OTC:ELEK) highlighted rising U.S. demand for used electric vehicles in Q1 2026 as fuel prices and an influx of off-lease EVs reshape buyer incentives. Used EV sales rose 12% YoY to 93,500 units, with average used EV prices about $1,300 above comparable gasoline vehicles. Charging infrastructure grew to 71,000

EV market finds footing after steep post-incentive decline

U.S. EV demand cools after tax credit expiration, but quarterly trends suggest the market may be finding a floor. On the Dash: EV demand is stabilizing, not rebounding, with sales likely to remain flat in the near term Incentive-driven volatility highlights the importance of pricing strategy and inventory discipline Long-term EV growth will depend on

Claude now works across all three major Office apps

Anthropic brings Claude directly into Microsoft Word. Anthropic already offered Claude add-ins for Excel and PowerPoint. Now the company is rounding out its Microsoft Office integration with a Word add-in. The AI can rewrite highlighted text, respond to comments in a document, and insert changes as tracked changes that users can accept or reject individually. Context can be

Global Ultra-Fast EV Charging Market: Growth, Trends,

Ultra-fast EV charging market set to surge to USD 68.4B by 2036, driven by rapid EV adoption and high-power charging demand. The global ultra-fast EV charging market is experiencing rapid expansion, reflecting the accelerating transition toward electric mobility and the growing need for high-speed charging infrastructure. Valued at USD 10.6 billion in 2025, the market

Fears of Anthropic’s latest model reach UK, biggest British banks, insurers and exchanges warned that…

Anthropic’s latest model, Claude Mythos, may now be raising concerns among the UK’s financial institutions. According to a report by The Financial Times (FT), financial regulators are holding urgent discussions with the UK government’s main cybersecurity watchdog and the country’s biggest banks to assess risks linked to the model’s ability to identify vulnerabilities in key

Microsoft is finally scrapping an Android app I didn’t even know existed

Summary Microsoft retires Outlook Lite for Android on May 25, 2026. Outlook Lite (5MB) was built for low-spec phones and 2G/3G networks, but it was missing some of Outlook’s features. After May 25, the app won’t provide mailbox access; emails will stay, but they will require the main Outlook app to view. Microsoft has been

Telegram Founder Updates App to Bypass Total Ban in Russia

Telegram founder Pavel Durov announced on Sunday, April 12, that the messaging app has upgraded its protocols to counter government censorship, advising Russian users to update the application to “stay connected despite the ban.” Writing on his official channel, Durov urged Russians to stock up on multiple VPN services and assist family members in doing

This Little-Known Trick Unlocks Dozens Of Apps And Games On Your Kindle

Marinel Sigue/BGR On the outside, the Kindle looks just like a mini tablet, with its wide touchscreen, minimal buttons, and thin build but under the hood, the two devices are far from similar. A tablet is capable of writing emails, tracking habits, and playing games, but a Kindle

MoistCr1TiKaL blasts Trump Mobile for slow deliveries

Streamer MoistCr1TiKaL, also known as Charlie, posted a twelve-minute-long video about Trump Mobile’s T1 Trump phone. Despite having ordered months ago, Charlie claims he is yet to receive the item. Trump Mobile, owned by the Trump Organization, promised to release the phones sometime in the summer of 2025. Charlie brings this information up and then

Hyundai Unveils Futuristic ‘Venus’ and ‘Earth’ EV Concepts for China

Got story updates? Submit your updates here. › Hyundai’s bold electric vehicle concepts showcase the company’s commitment to tailoring its designs to the evolving preferences of Chinese consumers.Oxford Today Hyundai has unveiled two new electric vehicle concepts, the ‘Venus’ and ‘Earth’, that showcase the automaker’s bold vision for the Chinese market. The sleek and stylish

How to Reclaim Your Android’s Original Speed in Under 10 Minutes

Stop treating your sluggish Android like it’s ready for the scrap heap. Most people assume that a stuttering screen or slow app launches mean the processor is failing, but the truth is usually much less expensive. Over time, your phone’s internal storage gets choked with digital junk-leftover data from apps you deleted months ago and

0
Would love your thoughts, please comment.x
()
x