Apr 2026
codexui-android first published on npm by account friuns
Malicious npm package → 29K weekly users' tokens silently exfiltrated
Level 1
A malicious npm package called codexui-android, downloaded over 29,000 times weekly, was silently stealing OpenAI Codex authentication tokens and sending them to an attacker-controlled server. The attack went undetected for roughly a month, with the malicious code injected after the package had already built a legitimate user base. Affected tokens include non-expiring refresh tokens, meaning attackers can impersonate victims indefinitely.
Apr 2026
codexui-android first published on npm by account friuns
Apr 12 2026
Domain anyclaw[.]store registered, coinciding with package upload
May 2026
Malicious exfiltration code injected roughly one month after initial publication
Jun 2 2026
Aikido Security researcher Charlie Eriksen publicly discloses the campaign
Dataconomy
1 day ago
Aikido Security
1 day ago
Dataconomy
1 day ago
Level 2
This attack exploits a structural weakness in how developers trust the open-source package ecosystem, using a fully functional tool to mask credential theft. The timing of the malicious injection, after the package had accumulated trust, reflects a deliberate delayed-activation strategy increasingly common in supply chain attacks. With OpenAI Codex now generally available on AWS Bedrock and embedded in enterprise IDE workflows, the blast radius of credential theft at this layer is no longer limited to individual developers but extends into corporate infrastructure.
Dataconomy
1 day ago
Aikido Security
1 day ago
Dataconomy
1 day ago
Level 3
This incident forces a reckoning across the AI developer toolchain: credential hygiene, package vetting, and default storage practices are all exposed as inadequate for the current threat environment. Enterprises that have integrated Codex into CI/CD pipelines via IDE plugins now face an urgent audit requirement. The simultaneous discovery of the Google API key revocation delay and similar AWS access key lag reveals that credential lifecycle management across the cloud industry is systemically broken.
Apr 2026
codexui-android published; anyclaw[.]store domain registered same month
May 2026
Malicious credential exfiltration code silently injected into the package
May 2026
OpenClaw Android app and BrutalStrike Codex app identified as secondary vectors using same payload
Jun 2 2026
Aikido Security publishes full disclosure; AWS simultaneously announces Codex GA on Bedrock
Charlie Eriksen
Lead threat researcher, Aikido
Aikido Security researcher who identified and disclosed the malicious package campaign
Igor Levochkin
Suspected threat actor
npm account owner friuns linked to the malicious codexui-android package
OpenAI
Affected platform vendor
Developer of Codex whose authentication credential storage practices are under scrutiny
Aikido Security
Threat intelligence discloser
Security firm that uncovered and publicly disclosed the supply chain attack
AWS
Enterprise distribution channel
Cloud provider now hosting Codex on Amazon Bedrock, expanding enterprise exposure surface
AI dev toolchains are now active high-value attack surfaces
Tech
The combination of non-expiring tokens, plaintext local storage, and npm's open publishing model creates a reproducible, scalable attack template. Security teams must treat AI coding agent credentials with the same rigor as cloud IAM keys.
Startups building on Codex face compounded risk exposure
Startups
Early-stage teams with limited security resources are disproportionately likely to have installed convenience packages without vetting. A stolen Codex token inside a startup's dev environment can yield access to proprietary codebases and AI pipeline configurations.
Trust in AI developer tooling becomes a competitive differentiator
Markets
Enterprise procurement cycles for AI coding agents will increasingly include security posture evaluation. Vendors who can demonstrate credential isolation and token rotation by default will gain ground against incumbents exposed by incidents like this.
Dataconomy
1 day ago
Aikido Security
1 day ago
Dataconomy
1 day ago
Level 4
The codexui-android campaign is likely the first publicly documented instance of AI agent credential theft at scale, but it will not be the last. As OpenAI Codex, GitHub Copilot, and competing agents proliferate across enterprise IDE stacks and cloud platforms, the credential surface area expands proportionally. The delayed-injection technique used here is already well understood by sophisticated threat actors and will be replicated across other AI tool ecosystems. Regulatory bodies and cloud providers will be forced to respond, but the window between exploitation and remediation is currently measured in months.
Apr 2026
Package published and domain registered; exfiltration infrastructure pre-positioned
May 2026
Malicious code injected after one month of legitimate operation and trust accumulation
Jun 2 2026
Public disclosure by Aikido Security; AWS announces Codex GA on Bedrock same day
Jun 2026
npm account owner claims investigation; partial removal of malicious code begins
Q3 2026
Anticipated regulatory and enterprise policy responses targeting AI toolchain credential standards
Charlie Eriksen
Lead threat researcher, Aikido
Aikido Security researcher who identified and disclosed the malicious package campaign
Igor Levochkin
Suspected threat actor
npm account owner friuns linked to the malicious codexui-android package
OpenAI
Affected platform vendor
Developer of Codex whose authentication credential storage practices are under scrutiny
AWS
Enterprise distribution channel
Cloud provider now hosting Codex on Amazon Bedrock, expanding enterprise exposure surface
npm registry
Compromised distribution vector
Open package repository through which the malicious package was distributed to 29,000 weekly users
AI agent authentication must be redesigned for adversarial environments
Tech
The current model of locally cached, plaintext, long-lived tokens is architecturally incompatible with a world where developers routinely install unvetted third-party packages. Short-lived tokens with hardware-backed storage must become the default, not an optional hardening step.
AI developer tool security becomes a VC and enterprise due diligence category
Markets
Investors and enterprise buyers will begin requiring security architecture documentation from AI coding agent vendors. Startups in the AI dev tool space that cannot demonstrate credential isolation will face deal friction and slower sales cycles.
Package registries face incoming regulatory scrutiny
Policy
The EU Cyber Resilience Act and US CISA secure-by-design guidance are on a collision course with npm's open publishing model. This incident provides concrete evidence regulators will cite when pushing for mandatory code-change auditing and maintainer identity verification on public registries.
AI Toolchain Supply Chain Attacks
accelerating
Threat actors are shifting from traditional software supply chain targets to AI-specific developer tools, exploiting trust in actively maintained packages and the high credential value of AI agent tokens.
Delayed-Injection Malware Technique
accelerating
Attackers are publishing legitimate, functional packages first to build download volume and community trust, then injecting malicious code in a subsequent update, defeating pre-publication security scans.
Non-Expiring Token Exploitation
emerging
As AI platforms issue long-lived or non-expiring refresh tokens for developer convenience, these become high-value persistent access credentials that can be harvested and monetized at scale.
Cross-Platform Credential Exfiltration
emerging
Single malicious npm packages are being reused across Android applications and desktop environments, multiplying the distribution surface of a single compromise payload.
Dataconomy
1 day ago
Aikido Security
1 day ago
Dataconomy
1 day ago
Level 5
This incident marks a structural inflection point: the AI developer toolchain is now a primary target category for credential theft, not an ancillary concern of general software supply chain security. The convergence of three forces, the proliferation of AI coding agents across enterprise stacks, the structural insecurity of open package registries, and the issuance of non-expiring high-privilege tokens, creates a threat environment that existing security frameworks were not designed to address. Organizations that treat this as an isolated npm incident rather than a systemic architecture failure will be repeatedly exposed. The simultaneous GA launch of Codex on AWS Bedrock is not ironic timing but a signal of how quickly the enterprise attack surface is expanding relative to the maturity of defenses.
Apr 2026
Package published; exfiltration domain registered within days of first npm upload
May 2026
Delayed-injection malicious code added; silent exfiltration begins across all 29,000 weekly installs
Jun 2 2026
Aikido Security discloses campaign publicly; AWS simultaneously launches Codex on Bedrock
Jun 2026
Package author begins partial remediation; full scope of credential theft unquantified
Q3 2026
Expected enterprise policy and regulatory responses targeting AI toolchain authentication standards
Charlie Eriksen
Lead threat researcher, Aikido
Aikido Security researcher who identified and disclosed the malicious package campaign
OpenAI
Affected platform vendor
Developer of Codex whose authentication credential storage practices are under scrutiny
AWS
Enterprise distribution channel
Cloud provider now hosting Codex on Amazon Bedrock, expanding enterprise exposure surface
npm registry
Compromised distribution vector
Open package repository through which the malicious package was distributed to 29,000 weekly users
Aikido Security
Threat intelligence discloser
Security firm that uncovered and publicly disclosed the supply chain attack
AI agent authentication architecture is a critical unresolved vulnerability
Tech
The combination of non-expiring refresh tokens, plaintext local storage, and open package distribution is an architecture that cannot be patched at the edges. Platform vendors must redesign credential issuance and storage from the ground up, treating the developer environment as an untrusted surface.
Regulators now have a concrete case for AI toolchain security mandates
Policy
The EU Cyber Resilience Act, CISA secure-by-design initiatives, and emerging AI-specific security frameworks all lack binding requirements for AI coding agent credential standards. This incident provides the documented precedent regulators need to advance mandatory token lifecycle and registry auditing requirements.
Security posture becomes a primary AI dev tool selection criterion
Markets
Enterprise procurement for AI coding agents is entering a phase where credential architecture, token rotation defaults, and supply chain provenance will be evaluated alongside capability benchmarks. Vendors who invest in security-first credential design now will capture enterprise deals that security-laggard competitors lose in compliance reviews.
AI Toolchain Supply Chain Attacks
accelerating
Threat actors are shifting from traditional software supply chain targets to AI-specific developer tools, exploiting trust in actively maintained packages and the high credential value of AI agent tokens.
Delayed-Injection Malware Technique
accelerating
Attackers publish legitimate functional packages first to build volume and trust, then inject malicious code in a subsequent update, systematically defeating pre-publication security scans.
Non-Expiring Token Exploitation
emerging
As AI platforms issue long-lived or non-expiring refresh tokens for developer convenience, these become high-value persistent access credentials that can be harvested and monetized at scale.
Cross-Platform Credential Exfiltration
emerging
Single malicious npm packages are being repackaged inside Android applications, multiplying distribution surface and defeating platform-level pre-publish scans through sandboxed execution.
Dataconomy
1 day ago
Aikido Security
1 day ago
Dataconomy
1 day ago