LWA-2026-6313 confirmed malware
@bobfrankston/mailx-store@0.1.58
Malicious code in @bobfrankston/mailx-store (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
@bobfrankston/mailx-store@0.1.58 is part of a malicious package ecosystem. The package depends on known-malware sibling packages (@bobfrankston/mailx-settings, @bobfrankston/mailx-types) that deliver malicious behaviour at runtime when the package is imported. The package has no verifiable repository URL and no documented legitimate purpose that would explain the dependency chain.
- analyzed by
- Leitwacht
- first seen
- Jul 4, 2026, 01:46 AM
- analyzed
- Jul 4, 2026, 01:48 AM
- weekly installs
- 632
Related advisories
- @bobfrankston/rmfmail@1.2.208
- @bobfrankston/rmfmail@1.2.209
- @bobfrankston/rmfmail@1.2.210
- chai-presentation@0.0.3
- chai-presentation@0.0.2
- chai-presentation@0.0.1
- chai-as-serialized@7.0.8
- chai-redirection@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.