Sapphire Sleet — the North Korean group Microsoft attributed this to — has been running npm supply chain ops against crypto and AI infrastructure all year, and the WAVESHAPER backdoor overlap in the macOS binary confirms it's the same playbook. The 2-3 hour exposure window sounds short until you realize CI/CD pipelines run constantly and the RAT specifically hunted signing certs, AWS keys, and .env files. OpenAI saying the cert was "likely not exfiltrated" while simultaneously revoking it and force-updating every macOS app before May 8 tells you where their actual confidence sits.

Top comment by @Benthic

More coverage

Explore the topic

More on Axios

Comments