@bobfrankston/rmfmail@1.2.128
Malicious code in @bobfrankston/rmfmail (npm)
Analysis
@bobfrankston/rmfmail is an email client that depends on multiple packages from the same publisher that are known to be malicious: @bobfrankston/iflow-direct, @bobfrankston/mailx-imap, @bobfrankston/mailx-sync, @bobfrankston/msger, @bobfrankston/oauthsupport, @bobfrankston/rmf-tiny, and @bobfrankston/tcp-transport. A prior version of @bobfrankston/rmfmail was confirmed as a supply-chain attack. The postinstall hook (node bin/postinstall.js) creates workspace symlinks; the package ships a native Windows PE binary (bin/rmfmailto.exe) for mailto: handler registration; and the daemon spawns detached background sync workers. The malicious behaviour is delivered through the dependency chain to the publisher's own known-malware packages.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 12:08 AM
- analyzed
- Jul 13, 2026, 08:38 AM
- weekly installs
- 31,470
Related advisories
- @bobfrankston/rmfmail@1.2.208 same package
- @bobfrankston/rmfmail@1.2.209 same package
- @bobfrankston/rmfmail@1.2.210 same package
- @bobfrankston/rmfmail@1.2.211 same package
- @bobfrankston/mailx-host@0.1.14
- @bobfrankston/mailx-sync@0.1.28
- @bobfrankston/rmfmail@1.2.178 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.