This Friday, OpenAI disclosed a security incident where its internal tools downloaded a maliciously tampered update of an open-source software library. The incident originated on March 31 when GitHub's automated process downloaded a version of the Axios library with embedded remote control code, though no user data or system breaches were detected. Affected users must update four macOS apps, including ChatGPT and Codex, before May 8 to avoid functional limitations caused by expired old certificates. OpenAI has revoked the old certificates and rotated to a new authentication mechanism, while collaborating with Apple to block the distribution of counterfeit apps.
