logo

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

ID: 11796a03-fbe6-5a6e-b6f1-ac2231c1701d

STIX ID: report--11796a03-fbe6-5a6e-b6f1-ac2231c1701d

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: [email protected] (The Hacker News)

...
...

## Executive Summary Security researchers disclosed a malicious supply-chain campaign in which a functioning npm package (codexui-android) and associated Android apps silently exfiltrate OpenAI Codex authentication tokens (including non-expiring refresh_tokens) to sentry.anyclaw.store, enabling indefinite account impersonation; the package and apps have significant distribution and the domain and package/version indicators are observable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.