{"data":{"id":"49f7917a-2c7c-4f77-8c02-c4b6cf049af4","title":"Attack targeting OpenAI Codex users exposes AI software supply chain risks","summary":"Attackers published a malicious npm package (a software library distribution platform) called codexui-android that appeared to be a legitimate tool for OpenAI Codex users but secretly stole authentication tokens and sent them to an external server. The attack exploited a supply chain gap where malicious code was hidden in the distributed package but not visible in the public source code repository, allowing the package to reach about 27,000 weekly downloads before detection. Security experts warn this reflects a broader vulnerability in AI software security, where developer tokens provide persistent access to accounts and are increasingly attractive targets as AI tools become widespread.","solution":"A cybersecurity researcher stated that 'enterprises should verify both the provenance of software packages and the consistency between published artifacts and their public source code.' Additionally, organizations should apply 'least-privilege and behavioral monitoring disciplines to AI tools' the same way they do for human user accounts, and maintain 'a complete inventory of what their AI tools can access, what credentials they inherit, and what external services they interact with.'","labels":["security"],"sourceUrl":"https://www.csoonline.com/article/4179815/attack-targeting-openai-codex-users-exposes-ai-software-supply-chain-risks.html","publishedAt":"2026-06-02T09:54:48.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain","data_extraction"],"issueType":"news","affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["OpenAI","Codex"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-06-02T09:54:48.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}