Observed Signal · Apr 10, 2026 · Security Incident · Source: OpenAI Blog · Impact: 3/5 · Sentiment: Neutral

OpenAI rotates macOS signing certificate after Axios compromise

Executive Signal Summary

On April 10, 2026 OpenAI disclosed a security incident tied to a compromised third-party developer library, Axios, that was part of a broader supply-chain attack. On March 31, 2026 a GitHub Actions workflow used in OpenAI’s macOS app‑signing process downloaded and executed a malicious Axios package (v1.14.1) and had access to code‑signing and notarization material. OpenAI found no evidence of user-data access, system compromise, or altered published software, but is treating the signing certificate as compromised: it engaged third‑party forensics, rotated and will revoke the certificate, published new macOS builds, and is asking macOS users to update apps by May 8, 2026 to avoid blocked launches. The root cause was a GitHub Actions misconfiguration (floating tag and missing minimumReleaseAge).

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A software supply‑chain compromise involving a major AI platform's app‑signing process affects developer trust and app distribution; OpenAI's remediation (certificate rotation, new builds, Apple coordination) is relevant to software security and app notarization practices but does not appear to have led to data exposure.

SIGNAL RADAR

Track GitHub Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • On March 31, 2026 a malicious version of the Axios npm package (v1.14.1) executed inside a GitHub Actions workflow used for OpenAI macOS app signing.
  • The affected workflow had access to a macOS code signing and notarization certificate used for ChatGPT Desktop, Codex App, Codex CLI, and Atlas.
  • OpenAI found no evidence that user data, systems, or published software were compromised or modified, but is treating the certificate as compromised and is revoking and rotating it.
  • OpenAI engaged a third‑party digital forensics firm, published new macOS builds signed with a rotated certificate, and is working with Apple to block notarization using the previous certificate.
  • Effective May 8, 2026 older macOS app versions signed with the previous certificate will no longer receive support and may be blocked by macOS security protections; OpenAI listed earliest updated versions for ChatGPT Desktop, Codex App, Codex CLI, and Atlas.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: OpenAI Blog•Published: Apr 10, 2026
Original Coverage Title: “Our response to the Axios developer tool compromise”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

SecurityMay 14, 2026

OpenAI: Hackers Stole Data After Supply-Chain Attack

OpenAI confirmed on May 14, 2026 that two employees’ devices were impacted by a recent supply‑chain attack that abused a compromised open‑source project (TanStack). After investigation, OpenAI said attackers accessed a limited subset of internal source code repositories and stole “only limited credential material,” but found no evidence that user data, production systems or intellectual property were compromised. TanStack disclosed that attackers published 84 malicious npm package versions during a six‑minute window; the malicious packages were designed to steal credentials and self‑propagate. As a precaution, OpenAI is rotating digital certificates used to sign products, an action that will require macOS users to update the app. The incident is part of a broader wave of supply‑chain compromises targeting developer tooling.

Read assessment
Software Supply-Chain SecurityApr 2, 2026

Axios npm Package Hijacked to Install Backdoor

A malicious supply-chain attack compromised a maintainer account for the widely used Axios npm package, adding a new dependency (plain-crypto-js) whose postinstall script downloaded and executed a remote-access trojan before self-deleting. The article frames this incident as part of a broader acceleration of automated, ecosystem-scale supply-chain attacks enabled by autonomous AI coding agents that install dependencies at machine speed. It describes a related campaign called TeamPCP that began by stealing a Trivy CI token, led to a self-propagating CanisterWorm across 66+ npm packages, and cascaded into Docker Hub, PyPI and the VS Code extension marketplace. Behavioral detection (e.g., Socket) that inspects package actions rather than CVE databases can detect novel malicious packages quickly; Socket detected the suspicious dependency in minutes, while the compromised Axios versions remained live for about three hours before removal. The piece warns that AI agents selecting and installing dependencies autonomously expands the attack surface and compresses the window for human review.

Read assessment
InfrastructureMay 31, 2026

23,000+ Repos Had Secrets Stolen via Compromised GitHub Action

A DevOps/security post documents a major supply-chain compromise of GitHub Actions where a popular action (tj-actions/changed-files) was hijacked in March 2025, exposing AWS keys, GitHub PATs, RSA private keys and npm tokens for over 23,000 teams. The vulnerability was tracked as CVE-2025-30066. The author analyzes this and related incidents (Ultralytics December 2024, Trivy February 2026), identifies recurring root causes (tag-pinned actions, pull_request_target misuse, overly permissive GITHUB_TOKEN scopes) and presents seven practical CI/CD hardening techniques: pin actions to commit SHAs, use OIDC, restrict GITHUB_TOKEN permissions, treat workflow files like production code, use automated workflow scanners (e.g., Zizmor), mirror critical actions/private registries, and enforce branch protection and deployment gates. The piece includes a checklist of quick wins and describes how the author applied these principles while building Nexloy.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.