看似合法的 Codex Remote UI 暗地里窃取你的 AI Token
aikido.dev | 博客 | #ai-security | #supply-chain | #malware | #credential-theft | #npm | #supply-chain-security | #openai-codex | #ai-tokens
摘要
npm 包 codexui-android 是一个真实好用的 OpenAI Codex 远程 UI(周下载 2.7 万),却在每次启动时将 access_token、refresh_token 等凭据外传至攻击者服务器,恶意代码只存在于发布包中、GitHub 上不可见。合法性本身正成为攻击载体。
- 发布时间
- 收录时间
Skip to content