Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
Blog post from Socket
The compromise of the popular Axios library has significantly affected software distribution pipelines, as illustrated by an incident in which a malicious version was executed within OpenAI's macOS app-signing workflow. This situation is part of a broader supply chain attack campaign linked to North Korean actors targeting Node.js maintainers through social engineering. OpenAI discovered the issue on March 31, 2026, when a compromised Axios version was executed via GitHub Actions, exposing sensitive macOS app-signing certificates. Despite mitigating factors likely preventing certificate exfiltration, OpenAI revoked and rotated its certificates, requiring users to update their apps. The root cause was a misconfigured CI pipeline that allowed the use of a floating tag instead of a specific commit hash, highlighting the severe risks of automated workflows that routinely pull third-party dependencies. While OpenAI reported no downstream compromise, the incident underscores the vulnerability of CI/CD pipelines to supply chain attacks, prompting varied reactions from developers and users regarding the incident's impact and the transparency of OpenAI's response.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.