LWA-2026-6330 confirmed malware

@bobfrankston/gcal@0.1.68

Malicious code in @bobfrankston/gcal (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

A Google Calendar CLI tool that depends on a known-malware OAuth library from the same publisher. The package's goauth.js imports authenticateOAuth() from @bobfrankston/oauthsupport, which handles the Google OAuth token exchange and can harvest the user's Google access and refresh tokens during authentication. The package also ships a Windows PE executable (bin/gcalics.exe, 215KB) for .ics file association. The postinstall hook is benign (prints a tip on Windows). The attack is credential theft via the malicious OAuth dependency during the legitimate-looking OAuth flow.

analyzed by
Leitwacht
first seen
Jul 5, 2026, 03:29 PM
analyzed
Jul 5, 2026, 03:30 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.