DANGEROUS: Codex try to execute JavaScript obfuscated code - Malware when i ask for check what it is

Resolved 💬 4 comments Opened Mar 24, 2026 by khanhnhat1660407 Closed Mar 24, 2026

What version of Codex CLI is running?

codex-cli 0.116.0

What subscription do you have?

Plus

Which model were you using?

gpt-5.3-codex

What platform is your computer?

Darwin 25.3.0 arm64 arm

What terminal emulator and version are you using (if applicable)?

Terminal.app

What issue are you seeing?

I asked the Codex: check <path>/babel.config.js, there is JavaScript obfuscated code, what is it?
And it executed the obfuscated code. In that situation, there's a 90% chance it was malware, but it executed the code without asking my permission.

What steps can reproduce the bug?

Uploaded thread: 019d1f89-9235-7340-8b33-c4257a71cdbe

What is the expected behavior?

Analyze the code before execution. Determine if the code is potentially malware and suggest a course of action.

Additional information

_No response_

View original on GitHub ↗

This issue has 4 comments on GitHub. Read the full discussion on GitHub ↗