LWA-2026-7296 confirmed malware
@bobfrankston/mailx-host@0.1.14
Malicious code in @bobfrankston/mailx-host (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Package @bobfrankston/mailx-host@0.1.14 is a thin wrapper that imports and re-exports from @bobfrankston/msger, a known-malicious dependency. The package has no repository, no lifecycle hooks, and its only purpose is to pull the malicious sibling package into the dependency tree of any project that installs it. Installing this package transitively installs the malicious @bobfrankston/msger payload.
- analyzed by
- Leitwacht
- first seen
- Jul 31, 2026, 03:16 AM
- analyzed
- Jul 31, 2026, 03:16 AM
Related advisories
- @bobfrankston/rmfmail@1.2.208
- @bobfrankston/rmfmail@1.2.209
- @bobfrankston/rmfmail@1.2.210
- postcss-animate-css-vars@2.0.3
- @vallensofficial/baileys@9.4.6
- @bobfrankston/mailx-sync@0.1.28
- log-min@1.0.13
- streak-metrics-math@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.