logo

OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident

ID: 2baa7de7-ab5a-5801-9d9d-a27ef8827893

STIX ID: report--2baa7de7-ab5a-5801-9d9d-a27ef8827893

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-04-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

In March 2026 a series of high-impact software supply chain attacks compromised widely used open-source tooling (notably the Axios npm package and the Trivy scanner), delivering cross-platform backdoors and credential-stealing malware that were leveraged to exfiltrate data, compromise downstream packages and CI workflows, and enable further intrusions; OpenAI disclosed its macOS signing workflow downloaded a poisoned Axios release, teams attributed activity to UNC1069 and TeamPCP, multiple organizations reported breaches, and mitigations (certificate rotation, CISA KEV listing for CVE-2026-33634, and vendor guidance) were enacted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.