{"id":15302,"date":"2026-06-01T04:14:00","date_gmt":"2026-06-01T04:14:00","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=15302"},"modified":"2026-06-01T04:14:00","modified_gmt":"2026-06-01T04:14:00","slug":"27000-obtain-codex-ui-software-secretly-stole-openai-refresh-tokens","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=15302","title":{"rendered":"27,000-Obtain Codex UI Software Secretly Stole OpenAI Refresh Tokens"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">A well-liked software program device utilized by 1000&#8217;s of cellular builders has been discovered stealing authentication tokens. On 27 Could 2026, Aikido Safety shared analysis with Hackread.com a couple of malicious npm package deal referred to as <code>codexui-android<\/code>. <\/p>\n<p class=\"wp-block-paragraph\">For context, it&#8217;s a extremely fashionable distant net person interface for OpenAI Codex, a man-made intelligence (AI) mannequin that writes code, gathering roughly 27,000 weekly downloads.<\/p>\n<p class=\"wp-block-paragraph\">Aikido Safety\u2019s researcher, Charlie Eriksen, found that this package deal ran a provide chain assault final month to steal person information.<\/p>\n<h3 id=\"hiding-in-plain-sight\" class=\"wp-block-heading\"><strong>Hiding in Plain Sight<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">Curiously, the attackers didn\u2019t use customary tips like <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/malware-infects-linux-macos-typosquatted-go-packages\/\">typosquatting<\/a> or account hijacking; as an alternative, they developed a genuinely useful gizmo. This was likely finished to kind an actual person base earlier than weaponising it. Furthermore, the malicious code doesn\u2019t exist within the public GitHub repository, and solely seems within the printed <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/hackers-poison-axios-npm-package-100m-downloads\/\">npm package deal<\/a>. This implies a typical supply code audit will surely miss it.<\/p>\n<p class=\"wp-block-paragraph\">The assault triggers instantly at module load. The very first line of dist-cli\/index.js imports a hidden script named <code>chunk-PUR7OUAG.js<\/code>. It rapidly checks for native credentials. If discovered, a knowledge exfiltration routine is launched to steal <code>access_token, id_token<\/code>, account ID, and the <code>refresh_token<\/code> from the <code>auth.json<\/code> file. Extra problematic is {that a} <code>refresh_token<\/code> doesn\u2019t expire; therefore, the attackers can impersonate the sufferer indefinitely.<\/p>\n<p class=\"wp-block-paragraph\">To cover the community visitors, the code sends the stolen information to a server endpoint named sentry.anyclawstore. This was chosen deliberately to mix in with regular Sentry error-reporting telemetry. Contained in the hidden supply map, the creator even left a transparent remark: \u201cShip tokens to our startlog endpoint (at all times)\u201d.<\/p>\n<h3 id=\"targeting-mobile-devices\" class=\"wp-block-heading\"><strong>Concentrating on Cell Gadgets<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">Researchers famous within the <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.aikido.dev\/blog\/codex-remote-ui-steals-ai-tokens\">weblog publish<\/a> that this menace actor additionally targets Android cellular units. The creator printed apps on the Google Play Retailer below the developer identification BrutalStrike, who additionally owns a professional cellular recreation with over 5 million downloads. <\/p>\n<p class=\"wp-block-paragraph\">Two particular apps, a paid productiveness app referred to as codex.app and one other referred to as \u201cOpenClaw Codex Claude AI Agent\u201d, include the identical malicious infrastructure.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"584\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-1024x584.png\" alt=\"\" class=\"wp-image-145848\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-1024x584.png 1024w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-300x171.png 300w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-768x438.png 768w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-1536x876.png 1536w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-380x217.png 380w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-800x456.png 800w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-1160x661.png 1160w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens.png 1712w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"\/><\/a><figcaption class=\"wp-element-caption\">Supply: Aikido Safety<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/77-malicious-android-apps-19-million-install-banks\/\">Android apps<\/a> simply cross Google\u2019s pre-publish safety scans as a result of the preliminary 26 MB APK file appears utterly clear. As soon as put in, the app extracts a Termux-derived Linux userland into personal storage and launches Node.js utilizing PRoot. It then runs a command to put in the most recent model of the npm package deal: pnpm add <code>codexui-android@newest<\/code>. The exfiltration has been lively since model <code><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"71121e15140904185c101f15031e181531415f405f4943\">[email\u00a0protected]<\/a><\/code>.<\/p>\n<p class=\"wp-block-paragraph\">When Eriksen confronted the creator, they briefly posted a remark claiming they misplaced entry to their npm account. They deleted it shortly after, changing it with a company assertion denying any credential theft. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"924\" height=\"358\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-1.png\" alt=\"\" class=\"wp-image-145850\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-1.png 924w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-1-300x116.png 300w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-1-768x298.png 768w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-1-380x147.png 380w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/05\/Malicious-Codex-UI-Tool-Secretly-Exfiltrates-OpenAI-Refresh-Tokens-1-800x310.png 800w\" sizes=\"auto, (max-width: 924px) 100vw, 924px\"\/><\/a><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">As of at present, the malicious software program package deal and the apps are nonetheless reside on-line.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAI developer tooling is turning into a high-value goal exactly as a result of the tokens are highly effective and long-lived\u2026 a menace actor invested actual effort into constructing a reputable, helpful venture to make use of as cowl. The legitimacy is the assault vector. As AI instruments proliferate and builders attain for productiveness shortcuts, count on extra of this,\u201d researchers concluded.<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="sC0QuOTy1rwhwle0cTD1"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A well-liked software program device utilized by 1000&#8217;s of cellular builders has been discovered stealing authentication tokens. On 27 Could 2026, Aikido Safety shared analysis with Hackread.com a couple of malicious npm package deal referred to as codexui-android. For context, it&#8217;s a extremely fashionable distant net person interface for OpenAI Codex, a man-made intelligence (AI) [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":15304,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[9277,2516,82,4017,7084,3598,6356,509],"class_list":["post-15302","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-27000download","tag-codex","tag-openai","tag-refresh","tag-secretly","tag-stole","tag-tokens","tag-tool"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15302","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15302"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15302\/revisions"}],"predecessor-version":[{"id":15303,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15302\/revisions\/15303"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/15304"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15302"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15302"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15302"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-01 16:51:45 UTC -->