LWA-2026-7064 confirmed malware

@bobfrankston/rmfmail@1.2.168

Malicious code in @bobfrankston/rmfmail (npm)

Analysis

@bobfrankston/rmfmail is a trojanized email client that steals saved browser credentials. At runtime it opens and exfiltrates Chromium WebView2 Login Data files (saved passwords). The postinstall hook runs JS that spawns detached subprocesses. The client bundle (client/app.bundle.js) fetches remote code and executes it via new Function. A bundled native PE executable (bin/rmfmailto.exe, 310KB) is shipped. The package depends on 8 known-malware packages and beacons telemetry to rmf39.aaz.lt/logit. DNS-based host discovery (dns.resolveMx) is used alongside host identity collection.

analyzed by
Leitwacht
first seen
Jul 23, 2026, 01:11 AM
analyzed
Jul 23, 2026, 04:14 PM
weekly installs
31,470

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.