LWA-2026-6303 confirmed malware
@bobfrankston/brother-label@1.1.12
Malicious code in @bobfrankston/brother-label (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
This finding is metadata-only: the package code in this version is a clean Brother label printer API/CLI with no obfuscation, no token theft, and no network exfiltration. No malicious behaviour was observed in this version.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 04:50 PM
- analyzed
- Jul 3, 2026, 04:53 PM
Related advisories
- @bobfrankston/rmfmail@1.2.208
- @bobfrankston/rmfmail@1.2.209
- @bobfrankston/rmfmail@1.2.210
- react-icons-svgo@1.5.4
- polymarket-trader-apis@0.1.0
- mdb-vite@1.5.2
- react-v17@20.0.1
- polymarket-apis@1.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.