LWA-2026-6307 confirmed malware
@bobfrankston/msger@0.1.388
Malicious code in @bobfrankston/msger (npm)
T1059.007 · JavaScriptT1204.002 · Malicious File
Analysis
The package ships precompiled native binaries (msgernative.exe, msgernative-linux-aarch64, msgernative-darwin-arm64) and runs a postinstall hook that copies them to a per-user bin directory. The JavaScript wrapper code is clean, but the opaque native binaries execute on every invocation and cannot be statically verified. The package has no repository and no verifiable provenance for its native binaries.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 07:14 PM
- analyzed
- Jul 3, 2026, 07:16 PM
- weekly installs
- 836
Related advisories
- @bobfrankston/rmfmail@1.2.208
- @bobfrankston/rmfmail@1.2.209
- @bobfrankston/rmfmail@1.2.210
- react-icons-svgo@1.5.4
- npm-rce-poc@1.0.13
- @withoneltd/lucky@0.1.4
- @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3
- mailconfirmer@3.3.11
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.