Model Releases
Our response to the Axios developer tool compromise
Axios, a widely used third-party JavaScript developer library with approximately 100 million weekly downloads, was compromised on March 31, 2026, as part of a broader software supply chain attack a...
Axios, a widely used third-party JavaScript developer library with approximately 100 million weekly downloads, was compromised on March 31, 2026, as part of a broader software supply chain attack attributed to actors believed to be linked to North Korea. Malicious versions of Axios injected a fake dependency whose sole purpose was to run a post-install script deploying a cross-platform remote access trojan. OpenAI found no evidence that its user data was accessed, that its systems or intellectual property were compromised, or that its software was altered, and confirmed that passwords and OpenAI API keys were not affected; the root cause — a misconfiguration in the GitHub Actions workflow — has since been addressed. Out of an abundance of caution, OpenAI will stop supporting older versions of its macOS apps on May 8, 2026.
Related
- We recently identified a security issue involving the third-party developer library Axios that was part of a broader industry incident. We f…
- Is OpenAI trying to become Anthropic, while Anthropic becomes OpenAI?
- CoreWeave inks multiyear cloud deal with Anthropic
- TraceSafe: A Systematic Assessment of LLM Guardrails on Multi-Step Tool-Calling Trajectories
Source: model-releases