Researchers reported that the npm package codexui-android, presented as a legitimate remote web UI for OpenAI Codex, contained hidden credential-stealing code in the published package that was absent from its public GitHub repository. The malicious code read users’ auth.json files on startup, collected access, refresh, and ID tokens along with account identifiers, and exfiltrated them to sentry.anyclaw[.]store/startlog after obfuscation. The package reportedly reached about 27,000 weekly downloads, with malicious behavior appearing from version 0.1.82 and remaining active for roughly a month; researchers warned that the stolen refresh tokens could enable persistent account impersonation.
The campaign also spread through at least two Google Play apps, including OpenClaw Codex Claude AI Agent and codex.app/Codex, which installed codexui-android@latest at runtime inside a bundled Linux and Node.js environment. Reporting linked the publisher to the alias BrutalStrike and described the operation as a supply-chain attack that used a genuinely functional tool and established user base as cover for token theft. Defenders were urged to revoke and rotate exposed OpenAI Codex credentials and investigate systems for downloads of affected package versions and outbound traffic to the identified exfiltration domain.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Cyber Security News reported on Aikido's findings about the malicious codexui-android package, adding technical detail that the stolen auth.json contents were XOR-encrypted with the key "anyclaw2026" and base64-encoded before exfiltration. The article also noted Aikido linked the publisher to the alias "BrutalStrike."
The account lazarusholic shared ENKI's Kimsuky report on Bluesky, highlighting JSONPing, Webex spoofing, and a new HttpSpy variant. The posts served as public amplification of the previously published campaign details.
Aikido reported that codexui-android, a legitimate-looking remote UI for OpenAI Codex with about 27,000 weekly downloads, had been used in a supply-chain campaign to steal Codex authentication data. The report also said the package was delivered through at least two Google Play apps that installed codexui-android at runtime.
The npm package codexui-android introduced hidden code in published versions starting with 0.1.82 that read Codex auth.json data and exfiltrated tokens and account information to sentry.anyclaw.store/startlog on startup. The malicious code was present in the published package but not in the public GitHub repository.
ENKI published a report on Kimsuky distributing a malicious mobile app via QR code, describing themes including JSONPing, Webex spoofing, and a new HttpSpy variant. This marks the public disclosure of the campaign details in the provided references.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
5 references tracked. Mallory keeps watching after this page renders.
enki.co.kr
Open sourcecybersecuritynews.com
Open sourceaikido.dev
Open sourcebsky.app
Open sourcebsky.app
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.