Viral Wire

OpenAI forces macOS app update after supply-chain attack

Update by June 12 or lose access to ChatGPT, Codex, Atlas.

Deep Dive

OpenAI has urgently advised all macOS users to update their ChatGPT, Codex, and Atlas desktop applications by June 12, 2026, following a supply-chain attack that compromised two employee devices on May 11. The attack exploited the TanStack npm library, a widely used JavaScript utility, to inject malicious code. Although OpenAI states there is no evidence of customer data exposure, the company is proactively rotating code-signing certificates and forcing updates to prevent further exploitation. Older app versions will cease to function after the deadline, making this a critical update for all users.

The incident highlights growing risks in software supply chains, especially for AI companies reliant on open-source packages. OpenAI is working with law enforcement and security researchers to trace the attack vector and has implemented additional scanning for npm dependencies. Users who have not yet updated are urged to do so immediately through the macOS App Store or the official OpenAI download page. This marks the second security-focused forced update from OpenAI this year, following a similar move in March to patch a remote code execution vulnerability in the ChatGPT desktop client.

Key Points
  • Attack exploited the TanStack npm library on May 11, compromising two OpenAI employee devices.
  • No customer data breach found, but OpenAI is rotating code-signing certificates as a precaution.
  • Older versions of ChatGPT, Codex, and Atlas macOS apps will stop working after June 12 deadline.

Why It Matters

Supply-chain attacks targeting AI tools require immediate user action to prevent potential data or system compromise.

📬 Get the top 10 AI stories daily