LWA-2026-6314 confirmed malware

@bobfrankston/mailx-imap@0.1.112

Malicious code in @bobfrankston/mailx-imap (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package depends on multiple sibling packages (@bobfrankston/iflow-direct, @bobfrankston/oauthsupport, @bobfrankston/mailx-store, @bobfrankston/mailx-settings, @bobfrankston/mailx-sync, @bobfrankston/mailx-types) that are known malware. Installing this package pulls in a malicious dependency chain. The package presents as a legitimate IMAP email client library but serves as a distribution vector for malware through its dependency tree.

analyzed by
Leitwacht
first seen
Jul 4, 2026, 01:47 AM
analyzed
Jul 4, 2026, 01:51 AM
weekly installs
1,380

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.