A malicious Codex UI npm package reached 27,000 weekly downloads before its discovery. The tool exfiltrated OpenAI refresh tokens to allow unauthorized account takeovers. This breach highlights a critical vulnerability in the developer supply chain. Practitioners must audit third-party dependencies immediately to prevent credential theft and secure their API environments.