Malicious Codex Tool Steals OpenAI Tokens from Developers

Malicious Codex Tool Steals OpenAI Tokens from Developers

First seen 29 May 2026, 02:11 UTC Aikido.DevCybernewsGbhackersCybersecuritynewsLetsdatascience+7 88% similarity 68.0

Article Content

Browse articles
ThreatCluster

A malicious npm package named 'codexui-android' has been discovered, which masquerades as a legitimate remote UI for OpenAI Codex. This tool, downloaded approximately 27,000 times weekly, has been silently exfiltrating users' authentication tokens for the past month. The malware operates by pulling additional malicious code post-installation, allowing it to evade detection during Google Play's security scans. The stolen tokens include long-lived refresh tokens, which can grant attackers indefinite access to user accounts. The threat actor designed the tool to appear functional and useful, making it particularly dangerous. The malicious code sends stolen data disguised as legitimate telemetry to an attacker-controlled server. The tool remains available for download on Google Play as of today, raising ongoing security concerns for developers using OpenAI Codex.

Key Points: • The 'codexui-android' npm package has been stealing OpenAI authentication tokens since April 2026. • The malware exploits a legitimate-looking tool, accumulating 27,000 downloads weekly before detection. • Stolen refresh tokens provide attackers with long-term access to user accounts without expiration.

ThreatCluster AI

Timeline

2026-04-27
Malicious code introduced in codexui-android
All published versions of the npm package began containing hidden malicious code, exfiltrating authentication tokens.
Aikido.Dev
2026-05-27
Aikido Security reports on the threat
Aikido Security published findings detailing the malicious activity of codexui-android, highlighting its stealthy nature.
Aikido.Dev
2026-05-29
Cybernews article confirms ongoing threat
Cybernews reported that the malicious package is still available for download on Google Play, emphasizing the urgency of the situation.
Cybernews

Community

Browse all →