OpenAI Responds to Axios npm Supply Chain Attack, Rotates macOS Certificates
ID: 3ca95d94-8ebd-55ed-9b91-0f6cd9c17c1f
STIX ID: report--3ca95d94-8ebd-55ed-9b91-0f6cd9c17c1f
Feed Name: The Cyber Express
OpenAI confirmed limited exposure to the Axios npm supply-chain attack (attributed to Lazarus/UNC1069) after a malicious Axios package ran in a macOS GitHub Actions app-signing workflow on March 31, 2026; OpenAI rotated and will revoke affected code-signing certificates, published new macOS builds, coordinated with Apple to block notarization with the old certificate, and found no evidence of user data compromise or tampered distributed software. The root cause was a GitHub Actions workflow misconfiguration (floating dependency tag and no minimum release age), illustrating growing risks in third-party dependency management.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
