Read More 2 minute read Security Artificial Intelligence 27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens A malicious Codex UI npm package with 27,000 weekly downloads was caught exfiltrating OpenAI refresh tokens, exposing developers to account takeover risks. byDeeba AhmedMay 31, 2026