logo

Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens

ID: bc5ef9f9-386c-552f-b4ea-0f4348fa0472

STIX ID: report--bc5ef9f9-386c-552f-b4ea-0f4348fa0472

Feed Name: Aikido Security's Blog

Threat Score
78/100

Date Published: 2026-05-27

Date Updated: 2026-07-24

...
...

A malicious npm package (codexui-android) published with active development and wide adoption contained top-level code that reads users' Codex auth.json and XOR-encrypts and POSTs the entire authentication blob (access_token, refresh_token, id_token, account ID) to sentry.anyclaw.store on every startup; an Android app on Google Play bootstraps and installs the package inside a Termux/PRoot userland so devices automatically pull and run the malicious package (exfiltration present since [email protected]).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.