Codex tokens were exfiltrated via a popular npm package, affecting users since v0.1.82 and enabling persistent account access. Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is advertised on GitHub and npm as a... [5503 chars]