Unknown
rss_thehackernews
·
rss_444c55f3b2a74069fc56e3e947410484
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Published Jun 1, 2026
Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI.
The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from the repository.
What
Affected AI Products
openai