OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident
ID: 2baa7de7-ab5a-5801-9d9d-a27ef8827893
STIX ID: report--2baa7de7-ab5a-5801-9d9d-a27ef8827893
Feed Name: The Hacker News
In March 2026 a series of high-impact software supply chain attacks compromised widely used open-source tooling (notably the Axios npm package and the Trivy scanner), delivering cross-platform backdoors and credential-stealing malware that were leveraged to exfiltrate data, compromise downstream packages and CI workflows, and enable further intrusions; OpenAI disclosed its macOS signing workflow downloaded a poisoned Axios release, teams attributed activity to UNC1069 and TeamPCP, multiple organizations reported breaches, and mitigations (certificate rotation, CISA KEV listing for CVE-2026-33634, and vendor guidance) were enacted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
