@bobfrankston/rmfmail@1.2.177
Malicious code in @bobfrankston/rmfmail (npm)
Analysis
@bobfrankston/rmfmail is a trojanized email client that steals browser-saved credentials. The postinstall hook (bin/postinstall.js) triggers credential theft: at runtime the package opens the WebView2/Chromium Login Data file (Chrome/Edge saved password store) via its dependency @bobfrankston/msger's native component (msgernative.exe). The package bundles native PE executables (bin/rmfmailto.exe, bin/rmfshare.exe) and ships a remote-code-execution dropper in client/app.bundle.js that uses new Function() to execute fetched code. It spawns detached background processes with windowsHide:true for stealth persistence, performs DNS MX resolution alongside host identity collection (DNS exfiltration pattern), and uses 120-second setTimeout delays to evade sandbox analysis. The package depends on 8 other known-malware packages from the same publisher ecosystem.
- analyzed by
- Leitwacht
- first seen
- Jul 27, 2026, 12:41 AM
- analyzed
- Jul 27, 2026, 09:54 AM
- weekly installs
- 31,470
Related advisories
- @bobfrankston/rmfmail@1.2.208 same package
- @bobfrankston/rmfmail@1.2.209 same package
- @bobfrankston/rmfmail@1.2.210 same package
- @bobfrankston/rmfmail@1.2.211 same package
- @bobfrankston/mailx-host@0.1.14
- @bobfrankston/mailx-sync@0.1.28
- @bobfrankston/rmfmail@1.2.178 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.