Security researchers found that “codexui-android,” an npm package advertised as a remote web UI for OpenAI’s Codex CLI and downloaded more than 29,000 times a week, had been secretly exfiltrating users’ non-expiring Codex OAuth refresh tokens to an attacker-controlled server disguised as telemetry infrastructure. The malicious code was introduced roughly a month after the package’s April 2026 publication and gave whoever held a stolen token the ability to silently and indefinitely impersonate the developer’s Codex account. A companion Android app distributing the same payload added tens of thousands of further installs to the exposure.