27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens
Hackread - Latest Cybersecurity News, Press Releases & Technolo…
May 31, 2026
A malicious Codex UI npm package with 27,000 weekly downloads was caught exfiltrating OpenAI refresh tokens, exposing developers to account takeover risks.
Discussion in the ATmosphere