codexui-android exfiltrates OpenAI Codex refresh tokens for ~7 weeks before Aikido disclosure
Aikido disclosed on 2026-06-02 that every codexui-android npm version from 0.1.82 (2026-04-13) through 0.1.125 silently exfiltrates the user's OpenAI Codex auth.json - access, refresh, and ID tokens - to sentry.anyclaw[.]store/startlog. The malicious code never appeared in the package's GitHub repository, and a companion Android app (50k+ installs) ships the same stealer.
Versions named here: 0.1.82, 0.1.83, 0.1.85, 0.1.88, 0.1.89, 0.1.90, 0.1.91, 0.1.92, 0.1.93, 0.1.94, 0.1.95, 0.1.96, 0.1.97, 0.1.98, 0.1.99, 0.1.100, 0.1.101, 0.1.102, 0.1.103, 0.1.104, 0.1.105, 0.1.106, 0.1.107, 0.1.108, 0.1.109, 0.1.110, 0.1.111, 0.1.112, 0.1.113, 0.1.114, 0.1.115, 0.1.116, 0.1.117, 0.1.118, 0.1.119, 0.1.120, 0.1.121, 0.1.122, 0.1.123, 0.1.124, 0.1.125