Back to Intel

Intel Node

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

lowadvisory2026-06-01T09:31:15+00:00source excerpt

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from the repository.

Read Original Source