OpenAI Codex tool with over 29,000 downloads linked to malicious npm supply chain attack stealing authentication tokens

OpenAI Codex tool with over 29,000 downloads linked to malicious npm supply chain attack stealing authentication tokens

A once-popular tool from OpenAI Codex, downloaded over 29,000 times, has been found to be part of a malicious npm supply chain attack. This attack aimed to steal authentication tokens, potentially giving attackers persistent access to users' systems. The incident underscores the growing threat of supply chain attacks and highlights the critical need for robust security measures in software development and distribution. This breach not only compromises individual users but also raises broader concerns about the security of open-source tools.

Original Source

Read the full article at Techradar →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.