Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • OpenAI’s Mac apps need updates thanks to the Axios hack  – CyberScoop
AttackFeed by Joe Wagner | OpenAI’s Mac apps need updates thanks to the Axios hack  - CyberScoop

OpenAI’s Mac apps need updates thanks to the Axios hack  – CyberScoop

Posted on April 13, 2026 By Matt Kapko No Comments on OpenAI’s Mac apps need updates thanks to the Axios hack  – CyberScoop
Attack Feeds

OpenAI updated its security certificates and is requiring all macOS users to update to the latest versions after determining its products, along with many others, were impacted by a widespread supply-chain attack that briefly infected a popular open-source library in late March, the company said in a blog post Friday.

The artificial intelligence vendor said it “found no evidence that OpenAI user data was accessed, that our systems or intellectual property was compromised, or that our software was altered.”

Yet, because a GitHub workflow the company uses to sign certificates for macOS applications downloaded and executed a malicious version of Axios, the company is treating the soon-to-be defunct certificate as compromised.

A North Korean hacking group injected malware into two versions of Axios after it compromised the lead maintainer’s computer via social engineering and took over his npm and GitHub accounts. Jason Saayman, the lead maintainer for Axios, said the malicious versions of the software were live for about three hours before removal. 

Google Threat Intelligence Group, which tracks the threat group as UNC1069, said the impact of the attack was broad with ripple effects potentially exposing other popular packages. The JavaScript libraries flow into dependent downstream software through more than 100 million and 83 million downloads weekly. 

The attack was discovered just weeks after a series of other open-source tools, including Trivy, were compromised by UNC6780, also known as TeamPCP, resulting in aggressive extortion attempts. 

OpenAI insists the malware that infected Axios did not directly impact its certificate, which is designed to help customers confirm they are downloading legitimate software. 

“The signing certificate present in this workflow was likely not successfully exfiltrated by the malicious payload due to the timing of the payload execution, certificate injection into the job, sequencing of the job itself, and other mitigating factors,” the company said in the blog post. “Nevertheless, out of an abundance of caution we are treating the certificate as compromised, and are revoking and rotating it.”

Older versions of OpenAI’s macOS apps may lose functionality and will no longer be supported when the certificate is fully revoked May 8, the company said.

OpenAI, which hired a third-party digital forensics and incident response firm to aid its investigation and response, pinned the root cause of the security issue on a misconfiguration in its GitHub workflow. The company said it corrected that error and worked with Apple to ensure fraudulent apps posing as OpenAI cannot use the impacted certificate.

The 30-day window is designed to minimize disruption for users, but OpenAI said it will speed up the revocation deadline if it identifies any malicious activity. The company did not immediately respond to a request for comment.

The post OpenAI’s Mac apps need updates thanks to the Axios hack appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025  – The Hacker News
Next Post: OpenAI Rotates macOS Certificates Following Axios Supply Chain Breach  – Hackread – Cybersecurity News, Data Breaches, AI and More ❯

You may also like

AttackFeed by Joe Wagner | 7 Key Features That Make Secure Browsers Safer  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
7 Key Features That Make Secure Browsers Safer  – Hackread – Cybersecurity News, Data Breaches, AI and More
May 4, 2026
AttackFeed by Joe Wagner | Vercel’s security breach started with malware disguised as Roblox cheats  - CyberScoop
Attack Feeds
Vercel’s security breach started with malware disguised as Roblox cheats  – CyberScoop
April 20, 2026
AttackFeed by Joe Wagner | How a simple consumer data breach spiralled into a national security crisis in US-South Korea relations  - Data and computer security | The Guardian
Attack Feeds
How a simple consumer data breach spiralled into a national security crisis in US-South Korea relations  – Data and computer security | The Guardian
April 24, 2026
AttackFeed by Joe Wagner | Mini Shai-Hulud returns, compromising hundreds of npm packages  - CyberScoop
Attack Feeds
Mini Shai-Hulud returns, compromising hundreds of npm packages  – CyberScoop
May 19, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.