OpenAI Codex tool with over 29,000 downloads linked to malicious npm supply chain attack stealing authentication tokens | Daily Reports Online
Researchers uncovered a malicious npm package posing as a Codex UI tool Attackers exfiltrated Codex authentication tokens, including non‑expiring refresh tokens Aikido Security also found two Android apps targeting Codex users A newly discovered supply-chain attack on npm is targeting software developers using OpenAI Codex. Codex is OpenAI’s coding assistant and software engineering agent that…










