@bobfrankston/rmfmail@1.2.137
Malicious code in @bobfrankston/rmfmail (npm)
Analysis
@bobfrankston/rmfmail@1.2.137 is a trojanized email client that steals browser-saved credentials from the WebView2 credential store. On install, the postinstall hook (bin/postinstall.js) copies a native binary (bin/rmfmailto.exe) to %LOCALAPPDATA%\rmfmail\bin\ and registers the package as the system mailto: handler. At runtime, the package accesses the WebView2 Login Data SQLite database at msger-native/bin/msgernative.exe.WebView2/EBWebView/Default/Login Data to harvest saved passwords. The package beacons telemetry to rmf39.aaz.lt/logit/ and hosts APK downloads at rmf39.aaz.lt/mailx/rmfmail.apk. It uses new Function to execute remotely-fetched code (client/app.bundle.js), spawns detached background processes for persistence, and performs DNS MX lookups alongside host identity collection. The package depends on multiple known-malware packages from the same publisher.
- analyzed by
- Leitwacht
- first seen
- Jul 15, 2026, 03:49 AM
- analyzed
- Jul 15, 2026, 09:07 AM
- weekly installs
- 31,470
Related advisories
- @bobfrankston/rmfmail@1.2.208 same package
- @bobfrankston/rmfmail@1.2.209 same package
- @bobfrankston/rmfmail@1.2.210 same package
- @bobfrankston/rmfmail@1.2.211 same package
- @bobfrankston/mailx-host@0.1.14
- @bobfrankston/mailx-sync@0.1.28
- @bobfrankston/rmfmail@1.2.178 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.