LWA-2026-7296 confirmed malware

@bobfrankston/mailx-host@0.1.14

Malicious code in @bobfrankston/mailx-host (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package @bobfrankston/mailx-host@0.1.14 is a thin wrapper that imports and re-exports from @bobfrankston/msger, a known-malicious dependency. The package has no repository, no lifecycle hooks, and its only purpose is to pull the malicious sibling package into the dependency tree of any project that installs it. Installing this package transitively installs the malicious @bobfrankston/msger payload.

analyzed by
Leitwacht
first seen
Jul 31, 2026, 03:16 AM
analyzed
Jul 31, 2026, 03:16 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.