@bobfrankston/gcal@0.1.68
Malicious code in @bobfrankston/gcal (npm)
Analysis
A Google Calendar CLI tool that depends on a known-malware OAuth library from the same publisher. The package's goauth.js imports authenticateOAuth() from @bobfrankston/oauthsupport, which handles the Google OAuth token exchange and can harvest the user's Google access and refresh tokens during authentication. The package also ships a Windows PE executable (bin/gcalics.exe, 215KB) for .ics file association. The postinstall hook is benign (prints a tip on Windows). The attack is credential theft via the malicious OAuth dependency during the legitimate-looking OAuth flow.
- analyzed by
- Leitwacht
- first seen
- Jul 5, 2026, 03:29 PM
- analyzed
- Jul 5, 2026, 03:30 PM
Related advisories
- @bobfrankston/rmfmail@1.2.208
- @bobfrankston/rmfmail@1.2.209
- @bobfrankston/rmfmail@1.2.210
- @bobfrankston/mailx-store-web@0.1.35
- debugcli@4.3.4
- polymarket-trader-apis@0.1.0
- polymarket-apis@1.1.0
- yiyuan-api@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.