LWA-2026-6803 confirmed malware

@bobfrankston/rmfmail@1.2.137

Malicious code in @bobfrankston/rmfmail (npm)

Analysis

@bobfrankston/rmfmail@1.2.137 is a trojanized email client that steals browser-saved credentials from the WebView2 credential store. On install, the postinstall hook (bin/postinstall.js) copies a native binary (bin/rmfmailto.exe) to %LOCALAPPDATA%\rmfmail\bin\ and registers the package as the system mailto: handler. At runtime, the package accesses the WebView2 Login Data SQLite database at msger-native/bin/msgernative.exe.WebView2/EBWebView/Default/Login Data to harvest saved passwords. The package beacons telemetry to rmf39.aaz.lt/logit/ and hosts APK downloads at rmf39.aaz.lt/mailx/rmfmail.apk. It uses new Function to execute remotely-fetched code (client/app.bundle.js), spawns detached background processes for persistence, and performs DNS MX lookups alongside host identity collection. The package depends on multiple known-malware packages from the same publisher.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 03:49 AM
analyzed
Jul 15, 2026, 09:07 AM
weekly installs
31,470

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.