OpenAI Codex tool with over 29,000 downloads linked to malicious npm supply chain attack stealing authentication tokens
1 June 2026 at 20:05
A tool started benign and turned sour after a little while, stealing tokens and granting persistent access.




