Anabelle Colaco
14 Apr 2026, 09:04 GMT+10
SAN FRANCISCO, U.S.: OpenAI said it had addressed a security issue linked to a third-party developer tool, adding that there was no evidence of user data exposure or compromise to its systems.
OpenAI said on Friday it had identified a security issue involving a third-party developer tool called Axios and is taking steps to protect the process that certifies its macOS applications are legitimate OpenAI apps.
The ChatGPT maker said it found no evidence that its user data was accessed, that its systems or intellectual property was compromised, or that its software was altered.
The company said it is updating its security certifications, requiring all macOS users to update their OpenAI apps to the latest versions to help prevent any risk of someone attempting to distribute a fake app.
According to OpenAI, Axios, a widely used third-party developer library, was compromised on March 31, as part of a broader software supply chain attack by actors believed to be linked to North Korea.
This attack led a GitHub Actions workflow used by OpenAI to download and execute a 'malicious' version of Axios. This workflow had access to a certificate and notarization material used for signing macOS applications, including ChatGPT Desktop, Codex, Codex-cli, and Atlas.
OpenAI said its analysis of the incident concluded that the signing certificate present in this workflow was likely not successfully exfiltrated by the 'malicious' payload.
Effective May 8, older versions of OpenAI's macOS desktop apps will no longer receive updates or support, and may not be functional, the ChatGPT maker said.
Passwords and OpenAI API keys were not affected by the third-party security issue, the company said, adding that the root cause of the security incident was a misconfiguration in the GitHub Actions workflow, which has been addressed.
Get a daily dose of Peking Press news through our daily email, its complimentary and keeps you fully up to date with world and business news as well.
Publish news of your business, community or sports group, personnel appointments, major event and more by submitting a news release to Peking Press.
More InformationSAN FRANCISCO, U.S.: OpenAI said it had addressed a security issue linked to a third-party developer tool, adding that there was no...
NEW YORK, New York - U.S. stocks moved higher Monday despite the weekend's breakdown in talks in Pakistan which hoped to result in...
LONDON, U.K.: Governments around the world are scrambling to contain rising energy costs and economic fallout from the Iran war, as...
DETROIT, U.S.: The cost of owning a car in the United States is climbing to new highs, with rising vehicle prices, financing costs...
FRANKFURT, Germany: Lufthansa is bracing for fresh disruption after its pilots' union called a two-day strike next week, escalating...
SAO PAULO, Brazil: Chinese investment in Brazil is increasingly shifting toward consumer-facing sectors, as companies target the country's...
SAO PAULO, Brazil: Chinese investment in Brazil is increasingly shifting toward consumer-facing sectors, as companies target the country's...
BERLIN, Germany: Porsche's global deliveries fell sharply in the first quarter, underscoring weakening demand in key markets and growing...
ISLAMABAD, Pakistan: U.S. Vice President JD Vance said talks between the United States and Iran ended early on April 12 without a peace...
SAN FRANCISCO/SHANGHAI: Tesla is exploring a return to more affordable electric cars with a new compact SUV under development, according...
RIO DE JANEIRO, Brazil: Brazil has placed Chinese automaker BYD on a government registry of employers linked to slavery-like labor...
Eric Swalwell and Tony Gonzalez to step down after allegations of misconduct involving staffers Democrat Eric Swalwell and Republican...
