OpenAI will revoke the macOS signing certificate tomorrow, May 8th, disabling outdated applications according to Beating.


OpenAI's macOS signing certificate will be revoked on May 8th, which will prevent outdated ChatGPT Desktop, Codex, Codex CLI, and Atlas from functioning properly and receiving updates.
Mac users should immediately update via in-app updates or download the latest version from the official OpenAI website.
The revocation stems from a March 31st npm supply chain attack targeting Axios, a JavaScript HTTP library with over 70 million weekly downloads.
The attacker used compromised maintainer credentials to publish malicious versions that included a fake dependency called plain-crypto-js, which automatically downloads a remote access trojan (RAT) affecting macOS, Windows, and Linux.
Microsoft attributed this attack to North Korean threat actor Sapphire Sleet.
OpenAI's GitHub Actions workflows automatically pulled the malicious version during macOS application builds, but the company found no evidence of certificate theft, user data leaks, or system intrusions.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin