OpenAI rotates macOS certs after Axios attack hit code-signing workflow
AI-summarised brief · reviewed before publication
OpenAI has rotated potentially exposed macOS code-signing certificates after a supply chain attack compromised a GitHub Actions workflow. The attack, linked to North Korean threat actors, downloaded a malicious Axios package, potentially exposing OpenAI's code-signing certificate. Although no evidence of compromise was found, OpenAI is treating the certificate as potentially compromised and is revoking and rotating it to protect users.