OpenAI Codex tool with over 29,000 downloads linked to malicious npm supply chain attack stealing authentication tokens

https://cdn.mos.cms.futurecdn.net/t3peL5Rd9E7bXzyHuQqJ5K-1920-80.jpg
  • Researchers uncovered a malicious npm package posing as a Codex UI tool
  • Attackers exfiltrated Codex authentication tokens, including non‑expiring refresh tokens
  • Aikido Security also found two Android apps targeting Codex users

A newly discovered supply-chain attack on npm is targeting software developers using OpenAI Codex.

Codex is OpenAI’s coding assistant and software engineering agent that can write and review code, fix bugs, run tests, and help developers build software with nothing but plain language input.

Recently it was discovered that a tool published on both GitHub and npm was actually malicious. It is called “codexui-android”, and it is described as a remote web user interface for the Codex platform. It attracted more than 29,000 weekly downloads, so it was rather popular. One of the reasons for its popularity is because it worked as advertised and appeared legitimate. The code published on GitHub remained “clean” the whole time, meaning the public...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE