<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/axios-supply-chain-attack-reaches-openai-macos-signing-pipel--thkcdvllt" -->

---
title: Axios Supply Chain Attack Reaches OpenAI macOS Signing...
description: A malicious version of the Axios npm package (1.14.1) was executed inside OpenAI&#x27;s macOS app-signing GitHub Actions workflow on March 31, 2026, exposing...
canonical: https://daily.dev/posts/axios-supply-chain-attack-reaches-openai-macos-signing-pipel--thkcdvllt
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipel... | daily.dev
og:description: A malicious version of the Axios npm package (1.14.1) was executed inside OpenAI&#x27;s macOS app-signing GitHub Actions workflow on March 31, 2026, exposing...
og:url: https://daily.dev/posts/axios-supply-chain-attack-reaches-openai-macos-signing-pipel--thkcdvllt
og:image: https://api.daily.dev/og/posts/tHkcdVLlT.png
og:image:alt: Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipel...
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipel...

**[Socket](https://daily.dev/sources/socketdev)** · 4 min read · 0 upvotes · 0 comments

## Summary

A malicious version of the Axios npm package (1.14.1) was executed inside OpenAI's macOS app-signing GitHub Actions workflow on March 31, 2026, exposing signing certificates used for ChatGPT Desktop, Codex, and Atlas. OpenAI responded by revoking and rotating its macOS code signing certificate, rebuilding affected apps, and requiring users to update before May 8, 2026. The root cause was a CI misconfiguration using a floating tag instead of a pinned commit hash, with no minimum release age check. No user data or production systems were confirmed compromised. The incident is part of a broader supply chain campaign attributed to North Korean actors targeting high-impact Node.js maintainers.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://socket.dev/blog/axios-supply-chain-attack-reaches-openai-macos-signing-pipeline-forces-certificate-rotation>

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#cicd](https://daily.dev/tags/cicd), [#openai](https://daily.dev/tags/openai), [#axios](https://daily.dev/tags/axios)

[View this post on daily.dev](https://daily.dev/posts/axios-supply-chain-attack-reaches-openai-macos-signing-pipel--thkcdvllt)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipel...","url":"https://daily.dev/posts/axios-supply-chain-attack-reaches-openai-macos-signing-pipel--thkcdvllt","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/axios-supply-chain-attack-reaches-openai-macos-signing-pipel--thkcdvllt"},"datePublished":"2026-04-11T03:52:27.953Z","dateModified":"2026-04-20T13:24:07.424Z","description":"A malicious version of the Axios npm package (1.14.1) was executed inside OpenAI's macOS app-signing GitHub Actions workflow on March 31, 2026, exposing...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/64a7b0ae3f7bb7340280f9add2c5c719?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/64a7b0ae3f7bb7340280f9add2c5c719?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Socket","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Socket","logo":"https://media.daily.dev/image/upload/s---oEn9czC--/f_auto/v1716187892/logos/socketdev","url":"https://daily.dev/sources/socketdev"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/axios-supply-chain-attack-reaches-openai-macos-signing-pipel--thkcdvllt","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,cicd,openai,axios","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Socket","item":"https://daily.dev/sources/socketdev"},{"@type":"ListItem","position":3,"name":"Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipel..."}]}
```

