LWA-2026-6855 confirmed malware
@bobfrankston/mlproc@1.0.11
Malicious code in @bobfrankston/mlproc (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
This package is a mail processing tool that reads emails from a queue directory, parses them, and routes them to recipients via SMTP or IMAP delivery. No lifecycle hooks execute on install. No obfuscation, no network exfiltration endpoints, and no credential theft mechanisms were found in the code. The package has a public GitHub repository and has been published across 10 versions over several months. No malicious behaviour was observed in this version.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 03:35 PM
- analyzed
- Jul 16, 2026, 03:37 PM
Related advisories
- @bobfrankston/rmfmail@1.2.208
- @bobfrankston/rmfmail@1.2.209
- @bobfrankston/rmfmail@1.2.210
- application-util@2.1.6
- date-utils-light@1.0.1
- http-req-lite@1.0.0
- @across-toolkit/eslint-config@99.0.1
- @hibachi-xyz/types@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.