LWA-2026-6312 confirmed malware

@bobfrankston/mailx-store-web@0.1.35

Malicious code in @bobfrankston/mailx-store-web (npm)

T1195.002 · Compromise Software Supply ChainT1071.001 · Web ProtocolsT1552.001 · Credentials In FilesT1082 · System Information Discovery

Analysis

Package @bobfrankston/mailx-store-web@0.1.35 sends verbose telemetry to rmf39.aaz.lt/logit/ via its vlog() function in worker-entry.ts, android-bootstrap.ts, and main-thread-host.ts. The dependency @bobfrankston/iflow-direct ships iflow-credentials.json containing a real Google OAuth client secret (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). The package depends on sibling packages (@bobfrankston/iflow-direct, @bobfrankston/mailx-sync, @bobfrankston/mailx-types) that ship the same OAuth credentials and telemetry infrastructure. No lifecycle hooks are present in this version.

analyzed by
Leitwacht
first seen
Jul 4, 2026, 01:48 AM
analyzed
Jul 4, 2026, 01:52 AM
weekly installs
770

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.