LWA-2026-6658 confirmed malware

@bobfrankston/rmfmail@1.2.128

Malicious code in @bobfrankston/rmfmail (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@bobfrankston/rmfmail is an email client that depends on multiple packages from the same publisher that are known to be malicious: @bobfrankston/iflow-direct, @bobfrankston/mailx-imap, @bobfrankston/mailx-sync, @bobfrankston/msger, @bobfrankston/oauthsupport, @bobfrankston/rmf-tiny, and @bobfrankston/tcp-transport. A prior version of @bobfrankston/rmfmail was confirmed as a supply-chain attack. The postinstall hook (node bin/postinstall.js) creates workspace symlinks; the package ships a native Windows PE binary (bin/rmfmailto.exe) for mailto: handler registration; and the daemon spawns detached background sync workers. The malicious behaviour is delivered through the dependency chain to the publisher's own known-malware packages.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 12:08 AM
analyzed
Jul 13, 2026, 08:38 AM
weekly installs
31,470

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.