macOS Flags ChatGPT App, Reinstallation Restores Notarization

Mac users have reported that macOS's built-in protection system, Xprotect, flagged older builds of the ChatGPT desktop app as malware and moved them to the Trash, after OpenAI revoked and rotated the macOS code-signing certificate used for ChatGPT Desktop, Codex, and Atlas following a March 31 supply-chain compromise of the Axios developer tool. OpenAI's own security team says no user data or software was compromised, and that reinstalling the app from OpenAI's official download page restores a notarized, launchable build; older versions lose support entirely after May 8, 2026. Separately, Malwarebytes reports a fake site, openew.app, has been impersonating OpenAI's download page to distribute a Windows credential stealer and a macOS strain called Odyssey Stealer, a fork of the Atomic Stealer family that targets browser passwords, crypto wallets, and Telegram sessions.
The two threads here are easy to conflate but need separate responses: the Xprotect warnings are a side effect of OpenAI's own precautionary certificate rotation, not evidence of a breach, while the openew.app campaign is genuine, unrelated malware exploiting the resulting confusion, and only one of the two is actually dangerous to click through.
What happened
According to OpenAI's own security disclosure, a GitHub Actions workflow used in OpenAI's macOS app-signing process executed a compromised version of the Axios developer library on March 31, 2026, as part of a broader npm supply-chain attack; the workflow had access to the certificate used to notarize ChatGPT Desktop, Codex, Codex CLI, and Atlas. OpenAI says its investigation found the certificate was likely not successfully exfiltrated, but the company is treating it as compromised out of caution, revoking and rotating it, and giving users until May 8, 2026 to update. As that transition has rolled out, Mac users have reported macOS's Xprotect system flagging older, still-validly-signed ChatGPT builds and moving them to the Trash; MacTrast and Forbes report reinstalling or updating via OpenAI's official download page restores a notarized, launchable app.
Timeline
A GitHub Actions workflow in OpenAI's macOS app-signing process executed a compromised version of the Axios npm package during a broader industry supply-chain attack.
OpenAI publicly disclosed the incident, said it found no evidence of compromised user data, and announced it would rotate its macOS code-signing certificate.
OpenAI's revocation deadline; older macOS app builds signed with the previous certificate lose support and may stop launching.
Malwarebytes reported a separate impersonation site, openew.app, distributing credential-stealing malware disguised as ChatGPT desktop installers.
Security context
Malwarebytes reports the openew.app site closely mimics OpenAI's real download experience and serves platform-specific payloads: a Windows credential-stealing loader distributed as Chat_GPT.exe, and, for macOS, a disk image installing Odyssey Stealer, a fork of the Atomic Stealer (AMOS) malware family. Malwarebytes says the macOS payload targets browser passwords, cookies, Telegram sessions, and cryptocurrency wallets, and attempts to replace legitimate Ledger and Trezor wallet apps with trojanized versions. This campaign is unrelated to OpenAI's certificate rotation; it opportunistically targets users searching for ChatGPT downloads via search ads and SEO.
For practitioners
For teams supporting end users, the two issues call for different responses: the Xprotect and notarization warnings are resolved simply by updating through OpenAI's official channels or in-app updater, while the openew.app campaign requires user education, since the fake site presents a convincing OpenAI-branded experience with a legitimate-looking HTTPS padlock. Organizations that deploy ChatGPT or similar AI desktop clients at scale should distribute updates through MDM or verified enterprise channels rather than relying on individual users to find the correct download link via search.
What to watch
- •Whether OpenAI accelerates its certificate revocation timeline if it finds evidence the exposed material was misused, as it said it would.
- •Additional takedown or blocklist action against openew.app and copycat domains.
- •Whether other AI vendors report similar supply-chain exposure through the same Axios npm compromise, which OpenAI describes as part of a broader industry incident.
Editorial analysis
This episode is a reminder that legitimate security remediation and opportunistic malware campaigns can look identical to end users, both show up as "something is wrong with my ChatGPT app." OpenAI's own disclosure is unusually detailed and, per its own account, found no evidence of actual compromise, but the resulting user confusion created an opening that a genuine malware campaign moved to exploit within weeks.
Key Points
- 1macOS's Xprotect flagged older ChatGPT app builds after OpenAI rotated its macOS code-signing certificate following a March 31 Axios supply-chain compromise.
- 2OpenAI found no evidence of actual compromise but set a May 8, 2026 deadline after which unupdated app builds lose support and may stop launching.
- 3Separately, a fake site, openew.app, distributes real malware, including macOS Odyssey Stealer, by impersonating OpenAI's ChatGPT download page.
Scoring Rationale
Well-corroborated dual-track security story verified against OpenAI's own detailed incident disclosure plus independent technical reporting (The Hacker News, AppleInsider) and threat-intel reporting (Malwarebytes) on a genuinely separate, active malware campaign. Notable for affecting a very widely used consumer AI desktop app, though OpenAI's own investigation found no evidence of actual compromise, which caps it below a major-tier score.
Sources
Public references used for this report.
Practice with real Hotels & Lodging data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Hotels & Lodging problems
