[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fc9dIF_WXhzDpU6CWVk4B-QbkY_EjJME1xsYI60t5ZBA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"f3f99b06-814b-4221-8095-d8e258e05dac","supply-chain-attack-compromises-code-signing-infrastructure-via-malicious-npm-package","0df5b213-4c19-436b-bbf6-b6eb1f7648ce","Supply Chain Attack Compromises Code-Signing Infrastructure via Malicious npm Package","OpenAI fell victim to a sophisticated supply chain attack when North Korean threat actors compromised an Axios maintainer and published a malicious npm package that executed within their GitHub Actions workflow. The attack gained access to sensitive macOS code-signing certificates, demonstrating how third-party dependencies can become attack vectors for critical infrastructure. While no evidence of certificate misuse was found, the incident highlights the cascading security risks when automated CI\u002FCD pipelines have excessive privileges and lack proper isolation from sensitive assets. This attack underscores the importance of treating third-party packages as untrusted code that requires rigorous validation and containment.","**Immediate actions:**\n- Audit all third-party packages in CI\u002FCD workflows and pin to specific verified versions\n- Rotate and revoke any certificates or secrets accessible to compromised workflows\n- Implement network isolation between CI\u002FCD environments and production certificate storage\n\n**Long-term improvements:**\n- Deploy automated dependency scanning tools to detect malicious packages before execution\n- Establish least-privilege access policies for CI\u002FCD workflows with minimal certificate access\n- Create separate signing environments that require manual approval for certificate operations\n\n**Detection measures:**\n- Monitor npm and package repository feeds for suspicious updates to critical dependencies\n- Implement behavioral monitoring for unusual certificate usage or signing activity",[12,13,14,15,16],"CIS Control 2.1","CIS Control 16.1","NIST SP 800-161","NIST AC-6","SLSA Framework Level 3","published","2026-04-13T18:09:53.912693+00:00","2026-04-13T18:09:53.815+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fopenai-rotates-macos-certs-after-axios-attack-hit-code-signing-workflow\u002F","openai-rotates-macos-certs-after-axios-attack-hit-code-signing-workflow-cad940","OpenAI rotates macOS certs after Axios attack hit code-signing workflow",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]