Standalone Codex account selection, authentication and launcher module.
An explicit login command obtains official Codex credentials and uploads an encrypted credential bundle to the package's default third-party service. Encryption does not prevent the configured service from receiving the credentials because it supplies the ingress key.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin-app.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/release-process-shutdown.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/release-process-shutdown.jsView on unpkgPackage source invokes a package manager install command at runtime.
assets/shortcut-bootstrap.cjsView on unpkg · L408Source file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/shortcut-bootstrap.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin-run.jsView on unpkgThis report applies to @tokensrc/codex@1.14.45.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin-app.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin-run.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/release-process-shutdown.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/release-process-shutdown.jsView on unpkgPackage source invokes a package manager install command at runtime.
assets/shortcut-bootstrap.cjsView on unpkg · L408Source file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/shortcut-bootstrap.cjsView on unpkg