Menu

Post image 1
Post image 2
1 / 2
0

OpenAI Codex Token Theft Exposes Persistent Risks in Developer AI Tools

WebProNews·Ava Callegari·3 months ago
#588sHaJZ
Reading 0:00
15s threshold

Developers reached for convenience. They installed a remote web UI for OpenAI’s Codex coding agent. Thousands did so every week. Now many face the quiet loss of long-lived authentication tokens that grant indefinite access to their accounts. The incident centers on codexui-android , an npm package promoted as a legitimate interface for Codex. It racked up more than 27,000 weekly downloads. Active development masked its darker purpose. The associated GitHub repository stayed clean. Malicious code appeared only in published npm versions. Supply Chain Deception Meets Persistent Credentials Aikido Security spotted the exfiltration. Researcher Charlie Eriksen laid it out plainly. “There’s a new playbook in the supply chain threat landscape, where someone builds something genuinely useful, growing a real user base. But all while stealing credentials.” He added, “It’s a functional tool that developers actually wanted rather than a typosquat or throwaway package.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More