OpenAI Codex Authentication Tokens Stolen in npm Attack
TL;DR. OpenAI Codex authentication tokens were compromised in a supply chain attack targeting the codexui-android npm package. - A malicious version of the JavaScript SDK was published, introducing a trojan that exfiltrated environment variables. - The attackers targeted developer credentials, specifically session cookies and OpenAI API keys. - OpenAI has revoked the compromised tokens to mitigate further unauthorized access.
- A malicious version of the codexui-android npm package was published.
- The trojan within the package exfiltrated environment variables, including authentication tokens.
- OpenAI confirmed the incident and revoked affected tokens to prevent misuse.