[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5XKuk6wLJRXWPaC-9SKSf-Jsw1CeM7jKAxoSeFUToec":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"400dae6d-60fd-45c3-b4c8-6bc86a252e12","malicious-npm-package-steals-openai-authentication-tokens","07854d12-9c86-4aa1-8cf5-6a280691c0da","Malicious npm Package Steals OpenAI Authentication Tokens","A compromised npm package named codexui-android infiltrated the software supply chain, stealing OpenAI Codex authentication tokens from over 29,000 weekly users. The malicious package exfiltrated sensitive credentials to attacker-controlled servers, demonstrating how supply chain attacks can compromise developer tools and steal valuable API access tokens. This incident highlights the critical need for package verification, dependency monitoring, and secure token management in development environments.","**Immediate actions:**\n- Audit all npm dependencies for the codexui-android package and remove if present\n- Revoke and regenerate all OpenAI Codex API tokens that may have been exposed\n- Scan development environments and applications for signs of credential exfiltration\n\n**Supply chain security:**\n- Implement package signature verification and dependency scanning tools in CI\u002FCD pipelines\n- Establish approved package registries and maintain allowlists for critical dependencies\n- Enable automated monitoring for suspicious package updates and new dependencies\n\n**Token management:**\n- Store API tokens in secure credential management systems rather than hardcoded in applications\n- Implement token rotation policies and least-privilege access controls for API credentials\n- Enable API usage monitoring and alerting for abnormal authentication patterns",[12,13,14,15,16,17],"CIS Control 2.7","CIS Control 16.7","NIST SP 800-161","NIST AC-2","NIST IA-5","OWASP SCVS","published","2026-06-01T12:07:43.096377+00:00","2026-06-01T12:07:43.013+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002Fopenai-codex-authentication-tokens.html","openai-codex-authentication-tokens-stolen-in-codexui-android-npm-supply-chain-at-444c55","OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"9b3a2eda-ad03-473b-b26c-9f53ca1db703","2026-06-01","afternoon","ThreatNoir Afternoon Brief — June 1","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-01\u002Fthreatnoir-afternoon-brief-2026-06-01.mp3"]