WorkThe story, in brief

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack - The Hacker News

27,000 developers unknowingly compromised. A fake Codex UI tool on npm just stole OpenAI authentication tokens at scale.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

Supply chain attacks targeting AI developer tools are now weaponizing npm ecosystems to harvest API credentials. This signals a critical blind spot in how AI infrastructure dependencies are vetted—and a new attack surface for enterprise AI deployments.

The key facts

6 to know
  1. 27,000+ downloads of malicious codexui-android npm package

  2. Attack vector: npm supply chain (legitimate-looking package name)

  3. Target: OpenAI Codex refresh tokens (API authentication credentials)

  4. Impact: Stolen tokens enable unauthorized API access and potential cost/data exploitation

  5. Discovery: Multiple security vendors (Aikido Security, CyberSecurityNews, gbhackers.com) identified and reported

  6. Risk scope: Any developer using the compromised package exposed to credential theft

Go to the source

Reuters Technologynews.google.com

Publisher excerpt: OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack The Hacker News 27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens Hackread Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens Aikido Security Legitimate-Looking Codex Remote UI…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work