@bobfrankston/mailx-store-web@0.1.35
Malicious code in @bobfrankston/mailx-store-web (npm)
Analysis
Package @bobfrankston/mailx-store-web@0.1.35 sends verbose telemetry to rmf39.aaz.lt/logit/ via its vlog() function in worker-entry.ts, android-bootstrap.ts, and main-thread-host.ts. The dependency @bobfrankston/iflow-direct ships iflow-credentials.json containing a real Google OAuth client secret (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). The package depends on sibling packages (@bobfrankston/iflow-direct, @bobfrankston/mailx-sync, @bobfrankston/mailx-types) that ship the same OAuth credentials and telemetry infrastructure. No lifecycle hooks are present in this version.
- analyzed by
- Leitwacht
- first seen
- Jul 4, 2026, 01:48 AM
- analyzed
- Jul 4, 2026, 01:52 AM
- weekly installs
- 770
Related advisories
- @bobfrankston/rmfmail@1.2.208
- @bobfrankston/rmfmail@1.2.209
- @bobfrankston/rmfmail@1.2.210
- debugcli@4.3.4
- polymarket-trader-apis@0.1.0
- polymarket-apis@1.1.0
- yiyuan-api@1.0.3
- polygon-gamma-apis@1.5.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.