Reviewed threat campaign
codexui-android token stealer
Aikido reported that the functional codexui-android npm package contained published code that exfiltrated OpenAI Codex authentication tokens even though the public source repository did not show the same malicious behavior.
Uncertainty
Aikido reported package behavior and download volume at investigation time. HOL has not independently measured the number of installations that actually exposed usable tokens.
Limitations
- Repository-to-package provenance verification and credential rotation remain required controls for this class of compromise.
Timeline
- · codexui-android token stealer was first observed in the reviewed source material.
- · The reviewed source published or updated its defensive analysis and remediation guidance.
Publication clock: 1787.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Guard coverage and non-coverage
- partial: coverage:stable:codex — Codex is a supported harness and package-install intent can be policy-controlled on eligible paths, but Guard does not claim it can retrospectively protect a token after malicious code has already read and transmitted it.
Defensive policy guidance
- Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.
Status: available. Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.
Sources
- Aikido: codexui-android token stealer · observed 2026-08-09