Daily Security Intel

Archives
Log in
Subscribe
September 21, 2026

[SecurityIntel] 21 Sep | OpenAI Codex Sandbox Escapes and Malicious npm Packages

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Monday, September 21, 2026

INTEL CONFIDENCE  52%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

OpenAI Codex Sandbox Escapes and Malicious npm Packages

CRITICAL

5

C2 IPs

0

OTX IOCs

2

ARTICLES

■ ANALYST TLDR

Today's threat landscape highlights critical vulnerabilities in development environments, specifically a runtime-evading malicious npm package campaign and sandbox escape flaws in OpenAI's Codex. The 'indexed-btree' npm package demonstrates a shift in supply chain attacks by executing malicious code during runtime rather than installation. Meanwhile, patched vulnerabilities in OpenAI Codex allowed researchers to escape sandboxes and execute arbitrary commands on host machines.

■ CRITICAL STORIES

HIGH#1

Malicious npm Package 'indexed-btree' Evades Install-Script Defenses

Threat actors are bypassing traditional static analysis and install-script monitoring by embedding malicious payloads directly into standard runtime execution paths of npm packages.

CRITICAL#2

OpenAI Patches Codex Sandbox Escape Vulnerabilities

Vulnerabilities in OpenAI's Codex allowed attackers to escape the execution sandbox and run arbitrary commands directly on the host developer's machine.

HIGH#3

Shift in Supply Chain Tactics Toward Runtime Execution

The discovery of the 'indexed-btree' campaign signals a tactical evolution where attackers avoid noisy installation scripts to evade automated security scanners.

■ CVEs IDENTIFIED

[CVE-TBD-1]

npm 'indexed-btree' package — Supply Chain Compromise & Malicious Runtime Code Execution

High

[CVE-TBD-2]

OpenAI Codex — Sandbox Escape & Host Command Execution

Critical

■ THREAT ACTORS

Unknown Threat Actor

Cybercriminal / Spyware Operator

Distributing malicious 'indexed-btree' npm packages to execute runtime attacks

Security Researchers

Red Team / Academic

Discovered and responsibly disclosed sandbox escape techniques in OpenAI Codex

■ ATT&CK TTPs

T1195.001
Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Malicious 'indexed-btree' package uploaded to npm registry
T1611
Escape to Host | Researchers escaped the OpenAI Codex sandbox to run host commands
T1059
Command and Scripting Interpreter | Execution of malicious runtime code and sandbox escape commands

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

OpenAI Codex — Sandbox escape allows arbitrary command execution on host machines — BleepingComputer

[P2 PATCH NOW]≤72h

npm 'indexed-btree' package — Malicious package executing runtime code to evade install-script defenses — BleepingComputer

■ RECOMMENDED ACTIONS TODAY

1[P1] Audit all Node.js projects for the presence of the malicious 'indexed-btree' npm package and immediately remove it if found.
2[P1] Verify that any local integrations with OpenAI Codex are updated to the latest patched version to mitigate sandbox escape risks.
3[P2] Implement runtime application self-protection (RASP) and behavior monitoring for Node.js applications to detect anomalous runtime execution, bypassing install-script-only checks.
4[P2] Restrict network and system privileges for developer environments running AI code-generation tools like OpenAI Codex to limit the impact of potential sandbox escapes.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 20 Sep | Critical Pre-Auth RCE Exploited in Orkes Conductor
Powered by Buttondown, the easiest way to start and grow your newsletter.