Another OpenAI hack puts ChatGPT Mac users on an update deadline
AI-summarised brief · reviewed before publication
OpenAI has disclosed a supply chain attack that exposed signing certificates used by Apple's security systems to verify trusted software. The "Mini Shai-Hulud" attack infected two employee devices through the TanStack npm ecosystem, but the company found no evidence of compromised customer data or intellectual property. OpenAI has rotated its signing certificates, re-signed affected apps, and is forcing Mac users to update ChatGPT and other desktop apps by June 12 to prevent potential misuse of the exposed credentials.
💡 Why It Matters
- · The update deadline underscores the importance of timely security patches in protecting users from potential malware threats.
- · The incident highlights the vulnerability of software ecosystems to supply chain attacks, which can have far-reaching consequences if left unaddressed.