Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens
aikido.dev | blog | #ai-security | #supply-chain | #malware | #credential-theft | #npm | #supply-chain-security | #openai-codex | #ai-tokens
Summary
A useful OpenAI Codex remote UI stole users' long-lived auth tokens on every invocation, with malicious code present only in the npm package. Aikido warns legitimacy itself is becoming the attack vector.
- Published
- Collected
Skip to content