high severityConfidence highHistorical record

codexui-android token stealer

Aikido reported that the functional codexui-android npm package contained published code that exfiltrated OpenAI Codex authentication tokens even though the public source repository did not show the same malicious behavior.

Also tracked as codexui-android

First observed
Apr 27, 2026
Last observed
May 27, 2026
Last reviewed
Sep 2, 2026
Tracking ended
Sep 8, 2026

Uncertainty and limitations

Read the evidence limits before acting on this record.

Aikido reported package behavior and download volume at investigation time. HOL has not independently measured the number of installations that actually exposed usable tokens.

  • Repository-to-package provenance verification and credential rotation remain required controls for this class of compromise.

Guard coverage and policy

What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.

Not covered, or partially covered

  • partial

    Codex is a supported harness and package-install intent can be policy-controlled on eligible paths, but Guard does not claim it can retrospectively protect a token after malicious code has already read and transmitted it.

  • Recipe available

    Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.

    Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.

Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.

Timeline

Reviewed events, oldest first, each tied to a verified source.

  1. First observed

    codexui-android token stealer was first observed in the reviewed source material.

  2. Disclosure

    The reviewed source published or updated its defensive analysis and remediation guidance.

Publication clock: 1787.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.

Reviewed artifacts

The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.

  • codexui-androidnpmpackage

Sources

Every claim on this record is traceable to the sources below.

Reviewed in full by HOL Guard Research.

Published
Last full review
Last modified

Report a correction

Record HGTC-2026-CODEXUI26