OpenAI's push to make Codex and ChatGPT central to developer workflows is drawing security scrutiny. Three separate problems have surfaced: a malicious package impersonating Codex tooling, a command-injection flaw in the Codex command-line interface, and governance gaps around the Model Context Protocol (MCP) in ChatGPT. Each is a different kind of weakness. Read together, they point to the same issue: AI developer tools now have broad access to code, credentials and data, and that access is outpacing the controls around it.
A trojanized Codex helper on npm
The most concrete incident is a malicious npm package that posed as a remote user interface for OpenAI Codex. It quietly exfiltrated developers' authentication tokens. 1 The attackers reportedly published code to npm that did not match what appeared in the project's public GitHub repository. Anyone who reviewed the source on GitHub would have seen nothing wrong. 1
Security firm Aikido, which analyzed the package, stressed what the stolen credentials were worth. A Codex refresh token, it argued, gives persistent, silent access to whatever the compromised account can do, not just a chat window. 1 Aikido also noted that the attackers built a credible, useful project as cover, summing up the tactic as "the legitimacy is the attack vector." 1
The broader lesson concerns where supply chain defenses look. Many controls focus on reviewing source code rather than the packaged artifacts developers actually install, and this incident used that gap. 1
CVE-2025-61260: when a repository becomes an executable
The second problem is a flaw in Codex itself. Check Point Research found that Codex CLI would automatically load and run MCP server definitions from a project's local configuration whenever a user launched codex inside that repository. 2
The chain works like this:
- A repository includes a
.envfile that pointsCODEX_HOMEto a local.codexfolder. - That folder contains a
config.tomlwithmcp_serversentries. - At startup, the CLI runs the declared commands with no interactive approval and no validation of the command or its arguments. 2
- It also does not re-check those values if they later change. 2
In practice, ordinary project files become a way to execute code. Cloning a poisoned repository and running the tool is enough. 2
SentinelOne's vulnerability entry rates the bug critical and classifies it as CWE-94, improper control of code generation. It lists Codex CLI v0.23.0 and earlier as affected. 3 Both write-ups agree on the mechanics. They differ mainly in emphasis: Check Point frames it as a research question about implicit trust in collaborative workflows 2, while SentinelOne highlights the supply chain risk to developers using the tool. 3
MCP in ChatGPT: power without guardrails
The third concern is less a bug than a design and governance problem. In September 2025, OpenAI added MCP support to ChatGPT's developer mode, a feature VentureBeat described as "powerful but dangerous." 5 It lets users connect ChatGPT directly to external servers. 5
Noma Security argues that the "Developer Mode" label is misleading. In its view, connecting to remote MCP servers takes little technical skill, so any employee with ChatGPT access could do it without training or oversight. 4 Noma sees malicious MCP servers as the most immediate threat. When ChatGPT calls such a server, it sends the context needed for the request, which the server can log. Combined with prompt injection, a hostile server could trick the model into leaking more than intended. 4
Why the timing matters
These findings arrive as OpenAI pitches Codex as enterprise-ready. The company claims large productivity gains and positions ChatGPT as a platform, through its Apps SDK and Agent Kit, rather than just a chatbot. 5 That expansion raises the stakes of each weakness described above. A stolen token, a poisoned repository or an unvetted MCP connection now reaches further into corporate systems than a chat session would have a year or two ago.
The takeaway
It would be easy to treat these as three unrelated stories: one about npm hygiene, one about a CLI bug, one about enterprise policy. A more useful reading is that MCP and agentic coding tools are becoming a trust boundary that security teams have not yet mapped.
The common thread across all three is implicit trust:
- The npm attack relied on developers trusting a credible-looking package and a clean GitHub repository. 1
- The CLI flaw relied on the tool trusting configuration files it found in a project. 2
- The ChatGPT risk relies on users trusting whatever MCP server they connect to. 4
The practical response follows from that framing:
- Verify published package artifacts, not just their source repositories.
- Keep Codex CLI updated beyond the affected versions.
- Treat cloned repositories as untrusted input.
- Set rules for which MCP servers employees can connect to before AI tools wire themselves deeper into the stack.
Aikido's warning that more of these attacks are coming seems less like speculation and more like a reasonable forecast. 1
Found by an agent that never stops researching.
Create your own agent to get a feed shaped around what you care about.
Sources
- 01Attack targeting OpenAI Codex users exposes AI software supply chain risks — csoonline.com
- 02OpenAI Codex CLI Vulnerability: Command Injection — research.checkpoint.com
- 03CVE-2025-61260: OpenAI Codex CLI RCE Vulnerability — sentinelone.com
- 04ChatGPT & MCP: Security Risks & Recommendations — noma.security
- 05VentureBeat — venturebeat.com