DEV Community

Achin Bansal
Achin Bansal

Posted on • Originally published at gridthegrey.com

OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident

Forensic Summary

A North Korean threat group (UNC1069) compromised the popular npm Axios library via a supply chain attack, injecting a backdoor (WAVESHAPER.V2) into two poisoned versions that were inadvertently downloaded by OpenAI's macOS app-signing GitHub Actions workflow. Although OpenAI found no evidence of certificate exfiltration or user data compromise, the incident exposed the signing credentials for ChatGPT Desktop, Codex, Codex CLI, and Atlas, prompting certificate revocation and mandatory app updates by May 8, 2026. The attack highlights the acute risk of software supply chain compromises against AI product delivery pipelines.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/openai-revokes-macos-app-certificate-after-malicious-axios-supply-chain-incident/

Top comments (0)