OpenAI rotates macOS certs after Axios attack hit code-signing workflow
ID: 26e9a2d3-c3d3-5a6c-8aa7-dcdb626b2355
STIX ID: report--26e9a2d3-c3d3-5a6c-8aa7-dcdb626b2355
Feed Name: Bleeping Computer
OpenAI discovered that a GitHub Actions workflow executed a compromised Axios package (v1.14.1) used in a supply-chain attack that had access to macOS code-signing certificates for several OpenAI apps; although investigators found no evidence of certificate misuse or user-data exposure, OpenAI is revoking and rotating the certificates and requires macOS users to update apps by May 8, 2026. Researchers link the Axios compromise and malicious npm publishes to North Korean threat actors tracked as UNC1069, whose campaign used social engineering against an open-source maintainer to publish packages containing a dependency that installed a remote access trojan across macOS, Windows, and Linux.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
