14:51
2026-05-29
letsdatascience.com
ai-tools
Codex UI Package Steals OpenAI Authentication Tokens
A malicious npm package named codexui-android, which amassed roughly 27,000 weekly downloads, secretly exfiltrated OpenAI Codex authentication tokens by sending the contents of users' auth.json files โฆ