← 목록으로

27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens

27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens

요약

A malicious Codex UI npm package with 27,000 weekly downloads was caught exfiltrating OpenAI refresh tokens, exposing developers to account takeover risks.

본문

A popular software tool used by thousands of mobile developers has been found stealing authentication tokens. On 27 May 2026, Aikido Security shared research with Hackread.com about a malicious npm p…

← 목록으로