OpenAI macOS app compromised in supply chain attack

💡Critical security update: OpenAI macOS app certificates compromised; update by June 12 to maintain app integrity.
⚡ 30-Second TL;DR
What Changed
Two employee devices were compromised via a supply chain attack.
Why It Matters
This incident highlights the risks of supply chain vulnerabilities in AI development environments. It necessitates stricter certificate management and security auditing for software distribution.
What To Do Next
If you use the OpenAI macOS app, immediately check for updates in the app settings to ensure you are running the latest version with the new security certificates.
Key Points
- •Two employee devices were compromised via a supply chain attack.
- •Code-signing certificates for the macOS application may have been leaked.
- •No evidence of customer data breach has been found to date.
- •Users must update the OpenAI macOS app before June 12 to ensure security.
🧠 Deep Insight
Web-grounded analysis with 11 cited sources.
🔑 Enhanced Key Takeaways
- •The supply chain attack specifically targeted the 'Tanstack' open-source software library, with an attacker publishing 84 malicious software versions across 42 Tanstack 'npm packages' on May 11, 2026.
- •The malicious software, if installed, was designed to download malware capable of stealing developer login credentials for cloud computing accounts, including GitHub tokens, npm publish tokens, AWS credentials, Kubernetes secrets, SSH keys, and .env files.
- •This incident is linked to a broader 'Mini Shai-Hulud' supply-chain campaign by the TeamPCP extortion gang, which targets developers by injecting malicious updates into popular software packages.
- •OpenAI's signing keys for macOS, Windows, iOS, and Android products were impacted, but only macOS users are required to update their applications due to Apple's notarization process.
- •This is the second reported supply chain attack affecting OpenAI's macOS app certificates in recent months, following a March 31, 2026, incident involving a malicious Axios JavaScript library attributed to a North Korean hacking group (UNC1069).
🛠️ Technical Deep Dive
- The attack leveraged a compromised open-source library, Tanstack, which is widely used for web development.
- Attackers exploited weaknesses in TanStack's GitHub Actions workflows and Continuous Integration/Continuous Deployment (CI/CD) configurations.
- This allowed the attackers to execute malicious code, extract tokens from memory, and publish malicious package versions directly through TanStack's legitimate release pipeline.
- The 'Mini Shai-Hulud' malware delivered in the campaign specifically targeted the theft of developer and cloud credentials, including GitHub tokens, npm publish tokens, AWS credentials, Kubernetes secrets, SSH keys, and .env files.
- Code-signing certificates are crucial for macOS security, as Apple's Gatekeeper and notarization systems use them to verify that software originates from a legitimate developer and has not been tampered with.
- A previous, similar incident on March 31, 2026, involved OpenAI's GitHub Actions workflow downloading and executing a malicious version of the Axios JavaScript library (versions 1.14.1 and 0.30.4).
- The Axios attack deployed a cross-platform backdoor known as WAVESHAPER.V2 and was attributed to a North Korean hacking group (UNC1069) that used social engineering to compromise a package maintainer's npm account.
🔮 Future ImplicationsAI analysis grounded in cited sources
⏳ Timeline
📎 Sources (11)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
Weekly AI Recap
Read this week's curated digest of top AI events →
👉Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: ITmedia AI+ (日本) ↗
