Discussion

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

Started by The Hacker News · 01 Jun 2026 14:14 · 18 Views · 0 Replies
Thread Starter #0
Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from the repository. What

Okumaya devam et...

You must be logged in to reply.

0 quotes selected