OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack - The Hacker News
27,000 developers unknowingly compromised. A fake Codex UI tool on npm just stole OpenAI authentication tokens at scale.

Why it matters
Supply chain attacks targeting AI developer tools are now weaponizing npm ecosystems to harvest API credentials. This signals a critical blind spot in how AI infrastructure dependencies are vetted—and a new attack surface for enterprise AI deployments.
The key facts
6 to know27,000+ downloads of malicious codexui-android npm package
Attack vector: npm supply chain (legitimate-looking package name)
Target: OpenAI Codex refresh tokens (API authentication credentials)
Impact: Stolen tokens enable unauthorized API access and potential cost/data exploitation
Discovery: Multiple security vendors (Aikido Security, CyberSecurityNews, gbhackers.com) identified and reported
Risk scope: Any developer using the compromised package exposed to credential theft
Go to the source
Reuters Technologynews.google.com
Publisher excerpt: OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack The Hacker News 27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens Hackread Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens Aikido Security Legitimate-Looking Codex Remote UI…