Cybersecurity
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Cyber RTJune 1, 20263 min read

Cybersecurity researchers have uncovered a malicious supply chain attack targeting developers using OpenAI Codex via a seemingly legitimate npm package, "codexui-android," which exfiltrates authentication tokens to an attacker-controlled server. The package, still available on GitHub, embeds malicious code while maintaining a clean repository. Additionally, an Android app, "OpenClaw Codex Claude AI Agent," also exploits this vulnerability. The attack highlights risks in AI developer tooling and credential revocation delays.
Cybersecurity researchers have uncovered a new malicious supply chain campaign targeting developers using OpenAI Codex through a seemingly legitimate remote web UI. The tool, named codexui-android, is promoted on platforms like GitHub and npm, boasting over 29,000 weekly downloads. Despite its malicious nature, the package remains available for download, raising concerns about its widespread reach and the potential impact on developers utilizing OpenAI Codex.
Unlike traditional attacks that rely on typosquatting or deceptive packages, this campaign embeds malicious code within a functional npm package that has been actively developed. The GitHub repository associated with the package appears clean, making it difficult for users to detect any foul play. According to Aikido Security researcher Charlie Eriksen, every invocation of the package has been exfiltrating Codex authentication tokens to a server controlled by the attackers.
The malicious changes were introduced about a month after the package was published, likely to build user trust and expand its reach. The npm account linked to the package is identified as "friuns," also known as Igor Levochkin. The package contains code that extracts Codex's authentication tokens from the "~/.codex/auth.json" file and sends them to a remote server disguised as Sentry, a legitimate application monitoring platform. The stolen data includes access tokens, refresh tokens, id tokens, and account IDs.
The refresh token, which does not expire, allows attackers to impersonate users indefinitely, granting them persistent access to whatever the Codex account can do. OpenAI's support documentation warns users to treat the "~/.codex/auth.json" file like a password, emphasizing the importance of not sharing it or committing it to public repositories. This highlights the critical nature of securing authentication tokens to prevent unauthorized access.
In addition to the npm package, the threat actor employs other delivery vectors to target Codex developers. Aikido observed an Android application named OpenClaw Codex Claude AI Agent that runs the npm package within a PRoot sandbox, sending Codex credentials to the same endpoint. The app, released by an entity named "BrutalStrike," has over 50,000 downloads, with similar exfiltration chains found in another app linked to BrutalStrike.
Upon contacting the package author on GitHub, Aikido received a response claiming the author had lost access to their npm account. However, the response was later edited to state that they were investigating the issue internally and had begun removing the affected functionality. Despite these claims, the author did not explain why the code was inserted into the npm package or why access to Codex tokens was necessary.
The discovery of this campaign underscores the growing trend of threat actors targeting AI developer tools and workflows to steal credentials and infiltrate the software supply chain. This development coincides with findings from a Belgian security company regarding a vulnerability in Google's API key revocation process, highlighting how credential revocation delays can be exploited to gain unauthorized access. These incidents emphasize the need for robust security measures and prompt response to potential vulnerabilities in developer tools and cloud environments.


