@bobfrankston/rmfmail@1.2.172
Malicious code in @bobfrankston/rmfmail (npm)
Analysis
@bobfrankston/rmfmail is a trojanized email client that steals saved browser credentials. At install time, the postinstall hook runs JS that spawns detached subprocesses. At runtime, the package opens and exfiltrates Chromium WebView2 Login Data files (saved passwords) from the installer's machine. It depends on 8 known-malware packages (@bobfrankston/iflow-direct, @bobfrankston/mailx-imap, @bobfrankston/mailx-sync, @bobfrankston/miscinfo, @bobfrankston/msger, @bobfrankston/oauthsupport, @bobfrankston/rmf-tiny, @bobfrankston/tcp-transport). The client-side bundle (client/app.bundle.js) contains a remote-code-execution pattern: it fetches code and executes it via new Function. The package beacons telemetry to rmf39.aaz.lt/logit. A bundled native PE executable (bin/rmfmailto.exe, 310KB) is also shipped. DNS-based host discovery (dns.resolveMx) is used alongside host identity collection.
- analyzed by
- Leitwacht
- first seen
- Jul 23, 2026, 01:59 PM
- analyzed
- Jul 23, 2026, 04:13 PM
- weekly installs
- 31,470
Related advisories
- @bobfrankston/rmfmail@1.2.208 same package
- @bobfrankston/rmfmail@1.2.209 same package
- @bobfrankston/rmfmail@1.2.210 same package
- @bobfrankston/rmfmail@1.2.211 same package
- @bobfrankston/mailx-host@0.1.14
- @bobfrankston/mailx-sync@0.1.28
- @bobfrankston/rmfmail@1.2.178 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.