The codexui-android npm package silently exfiltrated OpenAI Codex auth tokens to an attacker server for a month, affecting 29,000 weekly downloads.
Codex tokens were exfiltrated via a popular npm package, affecting users since v0.1.82 and enabling persistent account access ...
The tool gathered over 29,000 downloads before the malicious npm package was identified ...
Monday - Friday, 6:00 - 9:00 AM ET United States Monday - Friday 6a ET Europe Monday - Friday 13:00 CET Asia Monday - Friday 18:00 SIN/HK Australia Monday - Friday 20:00 SYD "Squawk Box" is the ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results