SECURITYTHE HACKER NEWS
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Cybersecurity researchers revealed a malicious supply chain attack targeting OpenAI Codex users via the codexui-android npm package, which is promoted as a remote web UI and has over 29,000 weekly downloads. The package remains available for download despite the security risks it poses.
Mentioned