
Codex Supply Chain Attack: OpenAI TanStack npm Breach Forces Cert Rotation — Update Before June 12
Codex supply chain attack traced to compromised TanStack npm package: OpenAI rotated code-signing certificates for Codex CLI, ChatGPT Desktop, and Atlas after Mini Shai-Hulud campaign hit two employees. macOS developers have until June 12, 2026 — update or your apps won't launch.
via OpenAI