logo

27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens

ID: a1b0a795-1bbb-5a01-8e37-3e4de50a1021

STIX ID: report--a1b0a795-1bbb-5a01-8e37-3e4de50a1021

Feed Name: HackRead

Threat Score
86/100

Date Published: 2026-05-31

Date Updated: 2026-05-31

Author: Deeba Ahmed

...
...

A widely downloaded npm package, codexui-android, and two Android apps have been found delivering a supply-chain infostealer that immediately runs at module load to harvest long-lived authentication tokens (access_token, id_token, refresh_token) from auth.json and exfiltrates them to a server masquerading as Sentry; the malicious code exists only in the published package (not in the public repo), evades source audits, and remains live on npm and the Play Store.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.