Impact
Public research describes a malicious npm package named codexui-android that presented itself as a Codex Remote UI tool while reading Codex authentication data from local auth files and sending it to attacker-controlled infrastructure [S1]. A repository dependency match is enough to require cleanup and credential review, but it does not prove that the package ran or that tokens were stolen.
Root Cause
The issue is a malicious package in the npm ecosystem. Aikido reports that the suspicious token-stealing behavior appeared in codexui-android starting with version 0.1.82 [S1]. Developers who installed and ran an affected build in an environment with Codex credentials may need to revoke sessions and rotate related credentials.
Covered by FixVibe
FixVibe's GitHub repo scans flag codexui-android in package manifests and lockfiles, showing the package, resolved version, source file and dependency path.
Remediation
Remove the affected codexui-android dependency, regenerate the active lockfile from a trusted registry state, rebuild CI images, devcontainers, Docker layers, Android or PRoot bootstraps, and deployed artifacts that may have cached it, then rerun the FixVibe GitHub repo scan. If the package may have started where Codex credentials existed, revoke Codex sessions and rotate OpenAI or Codex credentials through the provider workflow. Do not validate cleanup by executing the package, reading real auth files, fetching malicious tarballs for proof, or contacting reported exfiltration infrastructure.
