DANGEROUS: Codex try to execute JavaScript obfuscated code - Malware when i ask for check what it is
Resolved 💬 4 comments Opened Mar 24, 2026 by khanhnhat1660407 Closed Mar 24, 2026
What version of Codex CLI is running?
codex-cli 0.116.0
What subscription do you have?
Plus
Which model were you using?
gpt-5.3-codex
What platform is your computer?
Darwin 25.3.0 arm64 arm
What terminal emulator and version are you using (if applicable)?
Terminal.app
What issue are you seeing?
I asked the Codex: check <path>/babel.config.js, there is JavaScript obfuscated code, what is it?
And it executed the obfuscated code. In that situation, there's a 90% chance it was malware, but it executed the code without asking my permission.
What steps can reproduce the bug?
Uploaded thread: 019d1f89-9235-7340-8b33-c4257a71cdbe
What is the expected behavior?
Analyze the code before execution. Determine if the code is potentially malware and suggest a course of action.
Additional information
_No response_
This issue has 4 comments on GitHub. Read the full discussion on GitHub ↗