OpenAI Suffers Software Supply Chain Attack: Open-Source Library Axios Poisoned, Some macOS Apps Affected
13 hour ago / Read about 0 minute
Author:小编   

This Friday, OpenAI disclosed a security incident where its internal tools downloaded a maliciously tampered update of an open-source software library. The incident originated on March 31 when GitHub's automated process downloaded a version of the Axios library with embedded remote control code, though no user data or system breaches were detected. Affected users must update four macOS apps, including ChatGPT and Codex, before May 8 to avoid functional limitations caused by expired old certificates. OpenAI has revoked the old certificates and rotated to a new authentication mechanism, while collaborating with Apple to block the distribution of counterfeit apps.