@bobfrankston/rmfmail@1.2.168
Malicious code in @bobfrankston/rmfmail (npm)
Analysis
@bobfrankston/rmfmail is a trojanized email client that steals saved browser credentials. At runtime it opens and exfiltrates Chromium WebView2 Login Data files (saved passwords). The postinstall hook runs JS that spawns detached subprocesses. The client bundle (client/app.bundle.js) fetches remote code and executes it via new Function. A bundled native PE executable (bin/rmfmailto.exe, 310KB) is shipped. The package depends on 8 known-malware packages and beacons telemetry to rmf39.aaz.lt/logit. DNS-based host discovery (dns.resolveMx) is used alongside host identity collection.
- analyzed by
- Leitwacht
- first seen
- Jul 23, 2026, 01:11 AM
- analyzed
- Jul 23, 2026, 04:14 PM
- weekly installs
- 31,470
Related advisories
- @bobfrankston/rmfmail@1.2.208 same package
- @bobfrankston/rmfmail@1.2.209 same package
- @bobfrankston/rmfmail@1.2.210 same package
- @bobfrankston/rmfmail@1.2.211 same package
- @bobfrankston/mailx-host@0.1.14
- @bobfrankston/mailx-sync@0.1.28
- @bobfrankston/rmfmail@1.2.178 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.