Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

OpenAI confirms limited exposure tied to Axios npm breach

The malicious Axios version was executed within a GitHub Actions workflow tied to code-signing certificates used for OpenAI’s Mac apps.

byEmre Çıtak
April 13, 2026
in Cybersecurity, News
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

The axios npm supply chain attack has been linked to North Korea’s Lazarus Group and prompted OpenAI to confirm a limited exposure affecting its macOS applications. Google Threat Intelligence Group recognized the responsible group as UNC1069, a financially motivated entity known to be active since 2018.

OpenAI stated that while it was affected by the axios npm incident reported on April 1, there was no evidence of compromise to user data or internal systems. The malicious version of axios (v1.14.1) was executed in a GitHub Actions workflow on March 31, 2026, which was tied to code-signing certificates vital for OpenAI’s apps.

In response, OpenAI has initiated a full rotation of its macOS code-signing certificates. The company is treating the certificates as potentially compromised, despite internal analyses indicating they were likely not exfiltrated. As a precaution, users are required to update their macOS applications, as older versions will lose support after May 8, 2026.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

OpenAI has also coordinated with Apple to prevent any new notarization attempts using the old certificates, engaging a third-party digital forensics firm to investigate further. Actions taken include publishing new builds of affected apps, reviewing earlier software notarizations, and ensuring no unauthorized changes were made to distributed software.

The exposure was traced back to a misconfigured GitHub Actions workflow that utilized a floating tag rather than a fixed commit hash, lacking a minimum release age for dependencies. This misconfiguration increased the risk of integrating compromised packages, pointing to a broader vulnerability in development practices.

OpenAI emphasized that the incident solely affected macOS applications with no impact on iOS, Android, Windows, Linux, or web services. The company reassured users that no data or API keys were compromised, no passwords needed changing, and no malware signed by OpenAI has been detected.

OpenAI plans to revoke the old certificate on May 8, which will cause any software signed with it to be blocked by macOS security post-revocation. The axios npm attack underscores the growing risks associated with third-party software dependencies, reflecting both financial and strategic uses by state-sponsored groups.


Featured image credit

Tags: axiosopenAI

Related Posts

OpenAI improves health responses for free ChatGPT users

OpenAI improves health responses for free ChatGPT users

June 19, 2026
Adobe expands Firefly AI across Premiere, Illustrator, InDesign and Frame.io

Adobe expands Firefly AI across Premiere, Illustrator, InDesign and Frame.io

June 19, 2026
Spotify launches Reserved to give superfans early ticket access

Spotify launches Reserved to give superfans early ticket access

June 19, 2026
Google discontinues Nest Home Mini and Nest Audio

Google discontinues Nest Home Mini and Nest Audio

June 19, 2026
Instagram adds unique captions for each carousel slide

Instagram adds unique captions for each carousel slide

June 19, 2026
Steam Next Fest sees one in five demos labeled for generative AI

Steam Next Fest sees one in five demos labeled for generative AI

June 17, 2026

LATEST NEWS

OpenAI improves health responses for free ChatGPT users

Adobe expands Firefly AI across Premiere, Illustrator, InDesign and Frame.io

Spotify launches Reserved to give superfans early ticket access

Google discontinues Nest Home Mini and Nest Audio

Instagram adds unique captions for each carousel slide

Steam Next Fest sees one in five demos labeled for generative AI

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Novoresume

PolyAI

SeaArt

H2O.ai

Techpresso

Namecheap Free Logo Maker

Binaural Beats Factory

Lyricallabs

Jobscan

Vsub

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.