LWA-2026-7291 confirmed malware

@bobfrankston/mailx-sync@0.1.28

Malicious code in @bobfrankston/mailx-sync (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package @bobfrankston/mailx-sync@0.1.28 depends on @bobfrankston/iflow-direct (a previously-confirmed malicious package that has been removed from the registry) and @bobfrankston/tcp-transport. The package ships mail provider implementations (Gmail API, Outlook Graph, IMAP) with no install scripts in this version, but its dependency chain includes known-malware packages from the same namespace.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 07:44 PM
analyzed
Jul 30, 2026, 07:46 PM
weekly installs
764

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.