The Axios Supply Chain Attack Hit OpenAI’s Signing Pipeline. What Every Organisation Should Learn About Dependency Governance

The Axios Supply Chain Attack Hit OpenAI’s Signing Pipeline. What Every Organisation Should Learn About Dependency Governance

When a North Korean state actor compromised the Axios npm package on March 31, 2026, the blast radius did not stop at developer laptops. It reached OpenAI’s macOS code-signing pipeline — the system that certifies ChatGPT Desktop, Codex, Codex CLI, and Atlas as...