Popular Codex package caught exfiltrating authentication credentials
Home [Unofficial]
June 2, 2026
Researchers uncovered a malicious supply chain attack using a fake OpenAI Codex web UI called codexui-android that steals authentication tokens.
Discussion in the ATmosphere