Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens

Summary

A useful OpenAI Codex remote UI stole users' long-lived auth tokens on every invocation, with malicious code present only in the npm package. Aikido warns legitimacy itself is becoming the attack vector.
Published
Collected

original ↗

Related coverage

back