Attack targeting OpenAI Codex users exposes AI software supply chain risks
A malicious npm package called codexui-android, disguised as a legitimate remote user interface for OpenAI Codex, exfiltrated developer authentication tokens by hiding malicious code in the published package that was abs…