LWA-2026-6307 confirmed malware

@bobfrankston/msger@0.1.388

Malicious code in @bobfrankston/msger (npm)

T1059.007 · JavaScriptT1204.002 · Malicious File

Analysis

The package ships precompiled native binaries (msgernative.exe, msgernative-linux-aarch64, msgernative-darwin-arm64) and runs a postinstall hook that copies them to a per-user bin directory. The JavaScript wrapper code is clean, but the opaque native binaries execute on every invocation and cannot be statically verified. The package has no repository and no verifiable provenance for its native binaries.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 07:14 PM
analyzed
Jul 3, 2026, 07:16 PM
weekly installs
836

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.