Description
A malicious Codex UI npm package with 27,000 weekly downloads was caught exfiltrating OpenAI refresh tokens, exposing developers to account takeover risks.
Basic Information
ID
HACKREAD:4D8CE66CA7D4D8C25A00C5F9D69F75A9
Published
May 31, 2026 at 14:54