Published May 27, 2026 · Added May 28, 2026

Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens

Aikido Security reports that codexui-android, a remote web UI for OpenAI Codex with a real GitHub repo and tens of thousands of weekly npm downloads, quietly exfiltrated Codex, OpenAI, GitHub, SSH, and npm credentials from users' environments.

Aikido Security reports that codexui-android, a remote web UI for OpenAI Codex with a real GitHub repo and tens of thousands of weekly npm downloads, quietly exfiltrated Codex, OpenAI, GitHub, SSH, and npm credentials from users’ environments.

Read the original story.

Source: Aikido