OpenAI Codex Users Targeted in Attack, Highlighting AI Software Supply Chain Risks
A recent attack targeting users of OpenAI Codex has exposed significant risks in the AI software supply chain. The attack involved the theft of Codex refresh tokens, which provide persistent access to user accounts. This incident is part of a broader trend where attackers create legitimate-looking projects to mask malicious activities. The attack underscores vulnerabilities in software supply chains, particularly in AI developer tools, where security measures often focus on source code rather than the distributed software artifacts.