Malicious code in @ohos-ports/codex (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (516484e6fdd2f0f358d0973e15a4443ab6555c9eca3770e51a13ee3f5196b266) The package's package.json declares its dependency "@openai/codex" as a direct tarball URL: https://gitcode.com/api/v5/repos/OpenHarmonyPCDeveloper/JavaScript_Package_For_HarmonyOS/raw/packages/openai-codex-0.140.0.tgz?ref=main. The reference is mutable (branch 'main', no commit SHA, no integrity hash) and is hosted by a third-party org (OpenHarmonyPCDeveloper on gitcode.com) that is not the @openai publisher. On npm install, this tarball is fetched and placed into the installer's node_modules under the well-known @openai/codex name, so any code that resolves '@openai/codex' — including this package's own bin wrapper (`await import('@openai/codex/bin/codex.js')`) — loads content controlled by that third-party org rather than OpenAI. Because resolution happens through the dependencies field rather than a lifecycle script, `npm install --ignore-scripts` does not mitigate. The mutable branch reference means the content served at that URL can change at any time without a package republish.
Malicious code in @ohos-ports/codex (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (516484e6fdd2f0f358d0973e15a4443ab6555c9eca3770e51a13ee3f5196b266) The package's package.json declares its dependency "@openai/codex" as a direct tarball URL: https://gitcode.com/api/v5/repos/OpenHarmonyPCDeveloper/JavaScript_Package_For_HarmonyOS/raw/packages/openai-codex-0.140.0.tgz?ref=main. The reference is mutable (branch 'main', no commit SHA, no integrity hash) and is hosted by a third-party org (OpenHarmonyPCDeveloper on gitcode.com) that is not the @openai publisher. On npm install, this tarball is fetched and placed into the installer's node_modules under the well-known @openai/codex name, so any code that resolves '@openai/codex' — including this package's own bin wrapper (`await import('@openai/codex/bin/codex.js')`) — loads content controlled by that third-party org rather than OpenAI. Because resolution happens through the dependencies field rather than a lifecycle script, `npm install --ignore-scripts` does not mitigate. The mutable branch reference means the content served at that URL can change at any time without a package republish.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13210
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a73851fbf8831d5394ef82c
Added to database: 08/05/2026, 18:46:55 UTC
Last updated: 08/05/2026, 18:46:55 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.