HACKREAD

27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens_HACKREAD:4D8CE66CA7D4D8C25A00C5F9D69F75A9

Description

A malicious Codex UI npm package with 27,000 weekly downloads was caught exfiltrating OpenAI refresh tokens, exposing developers to account takeover risks.
Visit Original Source

Basic Information

ID HACKREAD:4D8CE66CA7D4D8C25A00C5F9D69F75A9
Published May 31, 2026 at 14:54

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.