OpenAI's macOS signing certificate will be revoked tomorrow (May 8th). After that, older versions of ChatGPT Desktop, Codex, Codex CLI, and Atlas won't launch or receive updates. If you're on a Mac, update now via the app or download from OpenAI's website.
The trouble started on March 31st with an npm supply chain attack. Axios — a JavaScript HTTP library with over 70 million weekly downloads — had two malicious versions (1.14.1 and 0.30.4) published by attackers using a stolen maintainer account. Those versions injected a fake dependency called plain-crypto-js that installed a remote access trojan (RAT) on macOS, Windows, and Linux. Microsoft attributed the attack to the North Korean hacking group Sapphire Sleet.
OpenAI's GitHub Actions workflow automatically pulled in the malicious version while building its macOS apps — and that workflow had access to the app signing certificate. OpenAI says the certificate likely wasn't stolen, but treated it as a leak anyway. It rotated the certificate and worked with Apple to block the old one's notarization channel. No evidence of user data breaches, system intrusions, or tampered software has been found; passwords and API keys are unaffected.
The root cause was a workflow configuration issue: dependencies were referenced using floating version tags instead of fixed commit hashes, and no minimumReleaseAge (a cooldown period after a new package release) was set. That meant the malicious versions were automatically pulled into the build as soon as they appeared.