LWA-2026-7065 confirmed malware

@bobfrankston/rmfmail@1.2.169

Malicious code in @bobfrankston/rmfmail (npm)

Analysis

@bobfrankston/rmfmail is a trojanized email client that steals saved browser credentials. At install time, the postinstall hook runs JS that spawns detached subprocesses. At runtime, the package opens and exfiltrates Chromium WebView2 Login Data files (saved passwords) from the installer's machine. It depends on 8 known-malware packages (@bobfrankston/iflow-direct, @bobfrankston/mailx-imap, @bobfrankston/mailx-sync, @bobfrankston/miscinfo, @bobfrankston/msger, @bobfrankston/oauthsupport, @bobfrankston/rmf-tiny, @bobfrankston/tcp-transport). The client-side bundle (client/app.bundle.js) contains a remote-code-execution pattern: it fetches code and executes it via new Function. The package beacons telemetry to rmf39.aaz.lt/logit. A bundled native PE executable (bin/rmfmailto.exe, 310KB) is also shipped. DNS-based host discovery (dns.resolveMx) is used alongside host identity collection.

analyzed by
Leitwacht
first seen
Jul 23, 2026, 01:26 AM
analyzed
Jul 23, 2026, 04:13 PM
weekly installs
31,470

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.