<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/openai-rotates-macos-certs-after-axios-attack-hit-code-signing-workflow-ehltud1kq" -->

---
title: OpenAI rotates macOS certs after Axios attack hit...
description: OpenAI is revoking and rotating macOS code-signing certificates after a GitHub Actions workflow executed a malicious version of the Axios npm package (v1.14.1)...
canonical: https://daily.dev/posts/openai-rotates-macos-certs-after-axios-attack-hit-code-signing-workflow-ehltud1kq
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: OpenAI rotates macOS certs after Axios attack hit code-signing workflow | daily.dev
og:description: OpenAI is revoking and rotating macOS code-signing certificates after a GitHub Actions workflow executed a malicious version of the Axios npm package (v1.14.1)...
og:url: https://daily.dev/posts/openai-rotates-macos-certs-after-axios-attack-hit-code-signing-workflow-ehltud1kq
og:image: https://api.daily.dev/og/posts/ehLTUD1Kq.png
og:image:alt: OpenAI rotates macOS certs after Axios attack hit code-signing workflow
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenAI rotates macOS certs after Axios attack hit code-signing workflow

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 0 upvotes · 0 comments

## Summary

OpenAI is revoking and rotating macOS code-signing certificates after a GitHub Actions workflow executed a malicious version of the Axios npm package (v1.14.1) on March 31, 2026, as part of a North Korean-linked supply chain attack. While no evidence of certificate compromise was found, OpenAI is treating it as potentially exposed out of caution. The old certificate will be fully revoked on May 8, 2026, after which apps signed with it will be blocked by macOS. Affected apps include ChatGPT Desktop, Codex, Codex CLI, and Atlas. Users must update to newly signed versions. The Axios attack has been attributed to North Korean threat actors (UNC1069) who used social engineering to compromise a project maintainer's account and publish malicious npm packages containing a remote access trojan.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/openai-rotates-macos-certs-after-axios-attack-hit-code-signing-workflow/>

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#openai](https://daily.dev/tags/openai), [#mac](https://daily.dev/tags/mac), [#axios](https://daily.dev/tags/axios)

[View this post on daily.dev](https://daily.dev/posts/openai-rotates-macos-certs-after-axios-attack-hit-code-signing-workflow-ehltud1kq)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"OpenAI rotates macOS certs after Axios attack hit code-signing workflow","url":"https://daily.dev/posts/openai-rotates-macos-certs-after-axios-attack-hit-code-signing-workflow-ehltud1kq","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/openai-rotates-macos-certs-after-axios-attack-hit-code-signing-workflow-ehltud1kq"},"datePublished":"2026-04-13T17:42:02.569Z","dateModified":"2026-04-20T13:24:07.424Z","description":"OpenAI is revoking and rotating macOS code-signing certificates after a GitHub Actions workflow executed a malicious version of the Axios npm package (v1.14.1)...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9598056baa320a4f4627a66498451d13?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9598056baa320a4f4627a66498451d13?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/openai-rotates-macos-certs-after-axios-attack-hit-code-signing-workflow-ehltud1kq","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,openai,mac,axios","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"OpenAI rotates macOS certs after Axios attack hit code-signing workflow"}]}
```

