Enterprise & Industry

OpenAI warns Mac users: update ChatGPT, Codex, Atlas by June 12 after npm supply-chain attack

Signing certificates exposed – patch these three Mac apps before the June 12 deadline.

Deep Dive

OpenAI says Mac users must update ChatGPT, Codex, and Atlas apps by June 12 after an npm supply-chain attack exposed signing certificates.

Key Points
  • OpenAI warns Mac users to update ChatGPT, Codex, and Atlas apps by June 12.
  • The attack compromised npm packages used in build pipeline, exposing signing certificates.
  • Only macOS builds are affected; Windows and Linux users are not at risk.

Why It Matters

Compromised code-signing certificates could let attackers distribute malware disguised as trusted OpenAI apps.