LWA-2026-7148 confirmed malware

@bobfrankston/rmfmail@1.2.178

Malicious code in @bobfrankston/rmfmail (npm)

Analysis

@bobfrankston/rmfmail is a trojanized email client that steals browser-saved credentials. The postinstall hook (bin/postinstall.js) triggers credential theft: at runtime the package opens the WebView2/Chromium Login Data file (Chrome/Edge saved password store) via its dependency @bobfrankston/msger's native component (msgernative.exe). The package bundles native PE executables (bin/rmfmailto.exe, bin/rmfshare.exe) and ships a remote-code-execution dropper in client/app.bundle.js that uses new Function() to execute fetched code. It spawns detached background processes with windowsHide:true for stealth persistence, performs DNS MX resolution alongside host identity collection (DNS exfiltration pattern), and uses 120-second setTimeout delays to evade sandbox analysis. The package depends on 8 other known-malware packages from the same publisher ecosystem.

analyzed by
Leitwacht
first seen
Jul 27, 2026, 01:26 AM
analyzed
Jul 27, 2026, 09:54 AM
weekly installs
31,470

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.