✦ For YouGeopoliticsTechFinanceHealthEnergySportsCulture
Tech & Science

OpenAI says a GitHub workflow used to sign its macOS apps downloaded a malicious Axios library on March 31, but no user data or internal system was compromised (Sam Sabin/Axios)

By TechMeme · 2026-04-10
OpenAI says a GitHub workflow used to sign its macOS apps downloaded a malicious Axios library on March 31, but no user data or internal system was compromised (Sam Sabin/Axios)
Why it matters: OpenAI’s macOS app signing pipeline was briefly compromised, but no user data was exposed.
OpenAI revealed that a GitHub workflow used to sign its macOS apps unintentionally fetched a maliciously altered Axios library on March 31. The compromised download did not lead to any exposure of user data or internal systems, and the issue was contained quickly.

Share this story

More tech & science → Read original →

Get tech & science in your inbox

The best stories, summarized daily. Free.

No spam. Unsubscribe anytime.