LWA-2026-6314 confirmed malware
@bobfrankston/mailx-imap@0.1.112
Malicious code in @bobfrankston/mailx-imap (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Package depends on multiple sibling packages (@bobfrankston/iflow-direct, @bobfrankston/oauthsupport, @bobfrankston/mailx-store, @bobfrankston/mailx-settings, @bobfrankston/mailx-sync, @bobfrankston/mailx-types) that are known malware. Installing this package pulls in a malicious dependency chain. The package presents as a legitimate IMAP email client library but serves as a distribution vector for malware through its dependency tree.
- analyzed by
- Leitwacht
- first seen
- Jul 4, 2026, 01:47 AM
- analyzed
- Jul 4, 2026, 01:51 AM
- weekly installs
- 1,380
Related advisories
- @bobfrankston/rmfmail@1.2.208
- @bobfrankston/rmfmail@1.2.209
- @bobfrankston/rmfmail@1.2.210
- @bobfrankston/mailx-store@0.1.58
- chai-presentation@0.0.3
- chai-presentation@0.0.2
- chai-presentation@0.0.1
- chai-as-serialized@7.0.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.