- Researchers uncovered a malicious npm package posing as a Codex UI tool
- Attackers exfiltrated Codex authentication tokens, including non‑expiring refresh tokens
- Aikido Security also found two Android apps targeting Codex users
A newly discovered supply-chain attack on npm is targeting software developers using OpenAI Codex.