# Malicious npm Packages Target Developer Credentials

**Published:** 2026-05-30T00:06:20.000Z  
**Topic:** On Chain Analysis  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/1977f5a1-8f71-4b6a-be05-6debfe19915a

Cybersecurity researchers warn of npm campaigns stealing OpenAI Codex tokens and cloud credentials via supply chain attacks.

Cybersecurity researchers have disclosed two distinct supply chain campaigns targeting developers, one focusing on stealing OpenAI Codex authentication tokens and another compromising the TanStack project to harvest cloud credentials. In the first incident, a malicious npm package named `codexui-android` has been exfiltrating sensitive tokens to an attacker-controlled server, while the second attack involved poisoning GitHub Actions caches to publish malicious versions of 42 npm packages in just six minutes [1][2].

**Key takeaways**
*   The `codexui-android` npm package has stolen OpenAI Codex refresh tokens, which do not expire, allowing for indefinite account impersonation [1].
*   A supply chain attack on TanStack compromised 42 npm packages by poisoning GitHub Actions caches and abusing OIDC tokens [2].

## Sources
1. The Hacker News — [OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack](https://thehackernews.com/2026/06/openai-codex-authentication-tokens.html)
2. InfoQ — [TanStack Details Sophisticated npm Supply Chain Attack That Compromised 42 Packages](https://www.infoq.com/news/2026/05/tanstack-supply-chain-attack/)

---
Cite as: TrendWatcher, "Malicious npm Packages Target Developer Credentials", https://www.trendwatcher.in/article/1977f5a1-8f71-4b6a-be05-6debfe19915a
