Menu

Categories

Tags

OpenAI confirms supply chain attack, forces macOS app update by June 2026

May 15, 2026 | Source: openai | Apple, OpenAI | 185 views 0 comments

OpenAI has confirmed that a supply chain attack targeting the TanStack ecosystem via a malicious NPM package infected two employee devices. While user data and core code remain untouched, the hackers made off with access credentials for internal code repositories—including code signing certificates for iOS, macOS, and Windows products.

To prevent attackers from using those stolen certificates to distribute fake apps, OpenAI is defensively rotating the certificates and setting a hard update deadline on macOS. All users of ChatGPT Desktop, Codex, and Atlas Browser on macOS must upgrade to the latest version by June 12, 2026. After that date, the old certificate will be revoked completely, and macOS will block old versions from launching or being installed fresh.

The attack exploited a timing gap in OpenAI’s own security rollout. The company admits it was already deploying stricter package-blocking policies, but the two infected employee devices hadn’t synced the latest configuration yet, letting the malicious component slip through. For containment, Apple’s macOS system automatically blocks new apps signed with a stolen certificate, so OpenAI opted for a nearly month-long update buffer instead of immediate revocation—avoiding a full disconnect for existing users. iOS and Windows clients are unaffected, and OpenAI confirms that user passwords, API keys, and other core data remain safe.

Leave a Reply

Your email address will not be published. Required fields are marked *