Loading article…

Cybersecurity researchers warn of npm campaigns stealing OpenAI Codex tokens and cloud credentials via supply chain attacks.
Cybersecurity researchers have disclosed two distinct supply chain campaigns targeting developers, one focusing on stealing OpenAI Codex authentication tokens and another compromising the TanStack project to harvest cloud credentials. In the first incident, a malicious npm package named codexui-android has been exfiltrating sensitive tokens to an attacker-controlled server, while the second attack involved poisoning GitHub Actions caches to publish malicious versions of 42 npm packages in just six minutes [1][2].
Key takeaways
codexui-android npm package has stolen OpenAI Codex refresh tokens, which do not expire, allowing for indefinite account impersonation [1].Coverage is mostly measured — 109 of 115 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Jun 1, 2026 · How we report
Ethereum captures roughly 70% of tokenized ETF issuances and a comparable share of the $475 million of tokenized ETF assets reported.
BlackRock, JPMorgan, and Franklin Templeton have issued or expanded tokenized fund products on the Ethereum network.
Broad market energy ETFs such as XLE and VDE have posted year‑to‑date returns of 32.63% and 33.09% respectively, driven by elevated crude prices and AI infrastructure demand.