OpenAI Revokes macOS Code-Signing Certs After Malicious Axios Package Hit CI Workflow
OpenAI is rotating its macOS code-signing certificates after a compromised Axios npm package (version 1.14.1) was executed within a GitHub Actions workflow on March 31, 2026, potentially exposing credentials used to sign ChatGPT Desktop and other apps.