[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fItMiw0OGdUTTnCdpt9ejULQY2uBQ_NK8hhfzwVHQ74o":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"1982bf2b-f660-4ef9-9c8e-f2da4efe81e9","supply-chain-attack-compromises-openai-through-malicious-axios-package","b3020996-7976-472d-8270-523f644eeb0d","Supply Chain Attack Compromises OpenAI Through Malicious Axios Package","North Korean threat actors successfully compromised OpenAI's systems by infiltrating the widely-used Axios JavaScript library through a supply chain attack. The attackers gained access to an Axios maintainer's npm account and published malicious packages containing a remote access trojan that executed within OpenAI's code-signing workflow. This incident highlights the critical risk posed by third-party dependencies and the importance of securing software supply chains, as even trusted libraries can become attack vectors when their maintainers' accounts are compromised.","**Immediate actions:**\n- Audit all third-party dependencies and verify package integrity using checksums or signatures\n- Implement package pinning to prevent automatic updates to potentially compromised versions\n- Review and rotate code-signing certificates that may have been exposed\n\n**Long-term improvements:**\n- Establish software bill of materials (SBOM) tracking for all third-party components\n- Implement multi-factor authentication and privileged access management for critical development accounts\n- Deploy automated dependency scanning tools that monitor for malicious packages\n\n**Detection measures:**\n- Monitor code-signing workflows for unusual activity or unauthorized certificate usage\n- Implement behavioral analysis on build systems to detect unexpected network connections or file modifications",[12,13,14,15,16],"CIS Control 2","CIS Control 16","NIST SP 800-161","NIST SSDF","SLSA Framework","published","2026-04-13T14:08:29.473827+00:00","2026-04-13T14:08:29.328+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.securityweek.com\u002Fopenai-impacted-by-north-korea-linked-axios-supply-chain-hack\u002F","openai-impacted-by-north-korea-linked-axios-supply-chain-hack-57a5d0","OpenAI Impacted by North Korea-Linked Axios Supply Chain Hack",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]