LWA-2026-6642 confirmed malware
@bobfrankston/tcp-transport@0.1.8
Malicious code in @bobfrankston/tcp-transport (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Analysis is metadata-only: the package source contains no install hooks, no network exfiltration, no credential theft, no obfuscation, and no executable payload. The package is a 2.9KB TypeScript TCP transport abstraction (BridgeTcpTransport) wrapping a native WebView bridge API (msgapi.tcp) with zero runtime dependencies. No malicious behaviour was observed in the published artifact.
- analyzed by
- Leitwacht
- first seen
- Jul 12, 2026, 05:40 PM
- analyzed
- Jul 12, 2026, 05:41 PM
- weekly installs
- 634
Related advisories
- @bobfrankston/rmfmail@1.2.208
- @bobfrankston/rmfmail@1.2.209
- @bobfrankston/rmfmail@1.2.210
- pure-folder-three@0.7.3
- @iana-rzms/bff-sdk@1.0.0
- express-request-engine@3.6.3
- @kkael/baileys@8.0.8
- dotnet-runtime-base@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.