OpenAI Revokes macOS Signing Certificate Tomorrow, May 8, Disabling Outdated Apps

According to Beating, OpenAI's macOS signing certificate will be revoked on May 8, rendering outdated versions of ChatGPT Desktop, Codex, Codex CLI, and Atlas inoperable and unable to receive updates. Users with Mac versions should update immediately through in-app updates or by downloading from OpenAI's official website.

The revocation stems from a March 31 npm supply chain attack targeting Axios, a JavaScript HTTP library with over 70 million weekly downloads. Attackers used compromised maintainer credentials to release malicious versions that injected a fake dependency called plain-crypto-js, which automatically downloaded remote access trojans (RAT) affecting macOS, Windows, and Linux. Microsoft attributed the attack to North Korean threat actor Sapphire Sleet. OpenAI's GitHub Actions workflow automatically pulled the malicious version during macOS app builds, but the company found no evidence of certificate theft, user data breaches, or system compromise.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments