In late March 2026, OpenAI discovered a security vulnerability linked to Axios, a widely used JavaScript HTTP client library. This issue arose when a GitHub Actions workflow, integral to OpenAI's macOS application signing process, inadvertently downloaded a compromised version of Axios. This breach could have potentially allowed attackers to exfiltrate a certificate essential for verifying the authenticity of macOS applications, including OpenAI's ChatGPT Desktop, Codex, Codex CLI, and Atlas. Despite the severity of the situation, OpenAI's internal investigation found no evidence that user data was accessed, systems were compromised, or software was altered. The company promptly revoked and rotated the affected certificate and updated its security certifications. As a result, OpenAI is advising all macOS users to update their applications to the latest versions to mitigate any potential risks. The incident underscores the growing threat of supply chain attacks in the software development industry. In this case, the attackers exploited a vulnerability in a third-party tool to gain access to OpenAI's application signing process. Such attacks can have far-reaching consequences, as they can lead to the distribution of malicious software that appears legitimate to users and platforms like the App Store. OpenAI's response highlights the importance of proactive security measures and transparency in addressing potential vulnerabilities. By swiftly identifying the issue, taking corrective actions, and communicating effectively with users, OpenAI has demonstrated a commitment to maintaining the integrity and security of its products. This event also serves as a cautionary tale for other technology companies that rely on third-party tools and libraries. It emphasizes the need for rigorous security practices, continuous monitoring, and rapid response strategies to protect against evolving cyber threats.