logo

OpenAI’s Mac apps need updates thanks to the Axios hack

ID: 29580550-1c8d-5ed9-a254-344abf0c72d4

STIX ID: report--29580550-1c8d-5ed9-a254-344abf0c72d4

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2026-04-13

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

OpenAI disclosed that a supply-chain attack tied to a North Korean-linked group (UNC1069) injected malicious code into Axios via a compromised maintainer; the malicious package executed in a GitHub signing workflow used by OpenAI for macOS apps, prompting OpenAI to treat a signing certificate as compromised, revoke and rotate it, and warn users to update affected macOS applications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.