27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens

A malicious Codex UI npm package with 27,000 weekly downloads was caught exfiltrating OpenAI refresh tokens, exposing developers to account takeover risks.

This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More

Read the original article: