{"schemaVersion":"guard-threat-campaign/v1","id":"HGTC-2026-CODEXUI26","slug":"codexui-android-token-stealer","title":"codexui-android token stealer","aliases":["codexui-android"],"summary":"Aikido reported that the functional codexui-android npm package contained published code that exfiltrated OpenAI Codex authentication tokens even though the public source repository did not show the same malicious behavior.","status":"published","severity":"high","confidence":"high","uncertainty":"Aikido reported package behavior and download volume at investigation time. HOL has not independently measured the number of installations that actually exposed usable tokens.","firstObservedAt":"2026-04-27T00:00:00.000Z","lastObservedAt":"2026-05-27T00:00:00.000Z","publishedAt":"2026-08-09T11:30:00.000Z","reviewedAt":"2026-08-09T11:20:00.000Z","expiresAt":"2026-09-08T23:59:59.000Z","reviewer":"HOL Guard Research","sources":[{"id":"source:aikido-codexui","label":"Aikido: codexui-android token stealer","url":"https://www.aikido.dev/blog/codex-remote-ui-steals-ai-tokens","sourceType":"other_primary","observedAt":"2026-08-09T11:20:00.000Z"}],"artifacts":[{"id":"artifact:codexui-android","artifactClass":"package","ecosystem":"npm","name":"codexui-android","version":null,"defanged":true}],"indicators":[],"timeline":[{"id":"timeline:first-observed","occurredAt":"2026-04-27T00:00:00.000Z","eventType":"first_observed","summary":"codexui-android token stealer was first observed in the reviewed source material.","sourceIds":["source:aikido-codexui"]},{"id":"timeline:disclosure","occurredAt":"2026-05-27T00:00:00.000Z","eventType":"disclosure","summary":"The reviewed source published or updated its defensive analysis and remediation guidance.","sourceIds":["source:aikido-codexui"]}],"coverage":[{"assertionId":"coverage:stable:codex","relationship":"partial","limitation":"Codex is a supported harness and package-install intent can be policy-controlled on eligible paths, but Guard does not claim it can retrospectively protect a token after malicious code has already read and transmitted it."}],"policies":[{"policyId":"policy:package-install-review","purpose":"Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.","status":"available","limitation":"Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted."}],"limitations":["Repository-to-package provenance verification and credential rotation remain required controls for this class of compromise."],"correctionHref":"/guard/security/campaigns/codexui-android-token-stealer/corrections"}