<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

OpenAI Hit by North Korean Supply Chain Attack Through Popular JavaScript Library

OpenAI hit by supply chain attack on Axios library, linked to North Korean hackers. App-signing certificates at risk, revocation by 2026.
Content Team

OpenAI confirmed Friday it was affected by a supply chain attack on Axios, a popular JavaScript library with over 100 million weekly downloads. North Korean hackers compromised an Axios maintainer's account in late March and published malicious packages that were live for just hours before detection.

The attack hit OpenAI's macOS app-signing process, potentially exposing certificates used to sign ChatGPT Desktop and other applications. While OpenAI believes the certificate wasn't compromised, they're revoking it as a precaution and will fully revoke it by May 2026.

Cybersecurity firms found evidence of compromise on 135 machines, with the malicious code executing in 3% of affected environments. The attack is linked to UNC1069, a North Korean group known for cryptocurrency theft.

Source: Security Week

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo