LWA-2026-6855 confirmed malware

@bobfrankston/mlproc@1.0.11

Malicious code in @bobfrankston/mlproc (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

This package is a mail processing tool that reads emails from a queue directory, parses them, and routes them to recipients via SMTP or IMAP delivery. No lifecycle hooks execute on install. No obfuscation, no network exfiltration endpoints, and no credential theft mechanisms were found in the code. The package has a public GitHub repository and has been published across 10 versions over several months. No malicious behaviour was observed in this version.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 03:35 PM
analyzed
Jul 16, 2026, 03:37 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.