OpenAI revokes macOS certs after TanStack breach

SkimNews Take
OpenAI's repeated certificate rotations and mandated updates reveal how the increasing interconnectedness of software dependencies forces companies to regularly re-authenticate their entire digital infrastructure to maintain security.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- OpenAI disclosed that two employee devices were compromised via the Mini Shai‑Hulud supply‑chain attack on TanStack, affecting limited internal code repositories but not production systems or IP.
- OpenAI isolated the impacted systems, revoked user sessions, rotated all credentials, and revoked signing certificates for iOS, macOS, and Windows products.
- OpenAI will revoke the current macOS code‑signing certificates on June 12 2026, requiring users of ChatGPT Desktop, Codex App, Codex CLI, and Atlas to update to the latest versions before that date.
- OpenAI previously rotated its macOS code‑signing certificates in mid‑April 2026 after a GitHub Actions workflow was compromised by the North Korean hacking group UNC1069, which delivered a malicious Axios library.
- TeamPCP claims to have compromised hundreds of packages across multiple AI and software firms, including TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI, highlighting a shift toward targeting shared software dependencies.
Why it matters: OpenAI users must update macOS apps before June 12 2026 to avoid being blocked, while the breach forces the company to tighten supply‑chain security, raising compliance costs for AI developers.




