• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

27,000-Obtain Codex UI Software Secretly Stole OpenAI Refresh Tokens

Admin by Admin
June 1, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


A well-liked software program device utilized by 1000’s of cellular builders has been discovered stealing authentication tokens. On 27 Could 2026, Aikido Safety shared analysis with Hackread.com a couple of malicious npm package deal referred to as codexui-android.

For context, it’s a extremely fashionable distant net person interface for OpenAI Codex, a man-made intelligence (AI) mannequin that writes code, gathering roughly 27,000 weekly downloads.

Aikido Safety’s researcher, Charlie Eriksen, found that this package deal ran a provide chain assault final month to steal person information.

Hiding in Plain Sight

Curiously, the attackers didn’t use customary tips like typosquatting or account hijacking; as an alternative, they developed a genuinely useful gizmo. This was likely finished to kind an actual person base earlier than weaponising it. Furthermore, the malicious code doesn’t exist within the public GitHub repository, and solely seems within the printed npm package deal. This implies a typical supply code audit will surely miss it.

The assault triggers instantly at module load. The very first line of dist-cli/index.js imports a hidden script named chunk-PUR7OUAG.js. It rapidly checks for native credentials. If discovered, a knowledge exfiltration routine is launched to steal access_token, id_token, account ID, and the refresh_token from the auth.json file. Extra problematic is {that a} refresh_token doesn’t expire; therefore, the attackers can impersonate the sufferer indefinitely.

To cover the community visitors, the code sends the stolen information to a server endpoint named sentry.anyclawstore. This was chosen deliberately to mix in with regular Sentry error-reporting telemetry. Contained in the hidden supply map, the creator even left a transparent remark: “Ship tokens to our startlog endpoint (at all times)”.

Concentrating on Cell Gadgets

Researchers famous within the weblog publish that this menace actor additionally targets Android cellular units. The creator printed apps on the Google Play Retailer below the developer identification BrutalStrike, who additionally owns a professional cellular recreation with over 5 million downloads.

Two particular apps, a paid productiveness app referred to as codex.app and one other referred to as “OpenClaw Codex Claude AI Agent”, include the identical malicious infrastructure.

Supply: Aikido Safety

The Android apps simply cross Google’s pre-publish safety scans as a result of the preliminary 26 MB APK file appears utterly clear. As soon as put in, the app extracts a Termux-derived Linux userland into personal storage and launches Node.js utilizing PRoot. It then runs a command to put in the most recent model of the npm package deal: pnpm add codexui-android@newest. The exfiltration has been lively since model [email protected].

When Eriksen confronted the creator, they briefly posted a remark claiming they misplaced entry to their npm account. They deleted it shortly after, changing it with a company assertion denying any credential theft.

As of at present, the malicious software program package deal and the apps are nonetheless reside on-line.

“AI developer tooling is turning into a high-value goal exactly as a result of the tokens are highly effective and long-lived… a menace actor invested actual effort into constructing a reputable, helpful venture to make use of as cowl. The legitimacy is the assault vector. As AI instruments proliferate and builders attain for productiveness shortcuts, count on extra of this,” researchers concluded.



Tags: 27000DownloadCodexOpenAIRefreshSecretlyStoleTokenstool
Admin

Admin

Next Post
Runway, the AI startup most lately valued at $5.3B, plans to make London its European headquarters and make investments $200M+ into the UK’s AI ecosystem by 2028 finish (Kai Nicol-Schwarz/CNBC)

Runway, the AI startup most lately valued at $5.3B, plans to make London its European headquarters and make investments $200M+ into the UK's AI ecosystem by 2028 finish (Kai Nicol-Schwarz/CNBC)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

May 18, 2025
Flip Your Toilet Right into a Good Oasis

Flip Your Toilet Right into a Good Oasis

May 15, 2025
Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

May 17, 2025
Reconeyez Launches New Web site | SDM Journal

Reconeyez Launches New Web site | SDM Journal

May 15, 2025
Apollo joins the Works With House Assistant Program

Apollo joins the Works With House Assistant Program

May 17, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Verify Level Launches AI Brokers That Suppose Like Attackers as Autonomous Exploitation Reaches Vital Risk Degree

Verify Level Launches AI Brokers That Suppose Like Attackers as Autonomous Exploitation Reaches Vital Risk Degree

June 1, 2026
Key Options to Search for in Procurement Software program

Key Options to Search for in Procurement Software program

June 1, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved