⤷ Title: The CodexUI Android Anomalous Supply-Chain Inversion: A Paradox of Developer Malevolence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 08:50:08 +0000
════════════════════════
⌗ Tags: #Malware #AnyClaw token harvesting #BrutalStrike developer repository poisoning #chunk_PUR70UAG.js backdoor #CodexUI Android token stealing #codexui_android npm package malware #OpenAI Codex key theft #OpenClaw Codex Claude AI Agent app #sentry.anyclaw.store exfiltration #software supply chain security #supply chain attack npm 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 08:50:08 +0000
════════════════════════
⌗ Tags: #Malware #AnyClaw token harvesting #BrutalStrike developer repository poisoning #chunk_PUR70UAG.js backdoor #CodexUI Android token stealing #codexui_android npm package malware #OpenAI Codex key theft #OpenClaw Codex Claude AI Agent app #sentry.anyclaw.store exfiltration #software supply chain security #supply chain attack npm 2026
Information Security News
CodexUI Android Steals User OpenAI Codex Auth Tokens
The popular npm package CodexUI Android has been caught secretly exfiltrating OpenAI Codex authentication tokens. Find out how to audit your environment.