LWA-2026-6313 confirmed malware

@bobfrankston/mailx-store@0.1.58

Malicious code in @bobfrankston/mailx-store (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

@bobfrankston/mailx-store@0.1.58 is part of a malicious package ecosystem. The package depends on known-malware sibling packages (@bobfrankston/mailx-settings, @bobfrankston/mailx-types) that deliver malicious behaviour at runtime when the package is imported. The package has no verifiable repository URL and no documented legitimate purpose that would explain the dependency chain.

analyzed by
Leitwacht
first seen
Jul 4, 2026, 01:46 AM
analyzed
Jul 4, 2026, 01:48 AM
weekly installs
632

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.