What Happened in the OpenAI Supply Chain Attack?
Hackers linked to the Shai-Hulud malware campaign compromised a TanStack npm package — a software tool developers use to manage coding packages. The malware infected two OpenAI employee devices that hadn’t yet received updated supply chain security protections. Investigators identified unauthorized access to a limited set of internal source code repositories connected to those employees.
What Was Exposed?
The affected repositories included code-signing certificates used for applications across macOS, iOS, Windows, and Android. These certificates are what operating systems use to verify that software comes from a trusted source and hasn’t been altered. OpenAI rotated the certificates and re-signed affected apps.
What Does This Mean for Users?
Mac users who use ChatGPT Desktop, Codex App, Codex CLI, or Atlas must install updated versions before June 12. After that date, Apple’s macOS security protections will block apps signed with the older certificates. OpenAI is forcing updates by rotating signing certificates rather than immediately revoking them, which could have broken existing installations.