The codexui-android npm package silently exfiltrated OpenAI Codex auth tokens to an attacker server for a month, affecting 29,000 weekly downloads.
The tool gathered over 29,000 downloads before the malicious npm package was identified ...
Six teams exploited Claude Code, Copilot, Codex, and Vertex AI in nine months. Every attack hit runtime credentials that IAM tools never tracked.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results