Incident29,000 Weekly Downloads of a Token Stealer
What Happened A malicious npm package named codexui-android infiltrated the supply chain of OpenAI Codex users, exfiltrating authentication tokens to an attacker-controlled server at sentry.anyclaw[.]














