LWA-2026-5588 MAL-2026-5927 ↗ confirmed malware

aillmgen@4.0.2

Malicious code in aillmgen (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

On installation, this package runs a preinstall hook that shells out to the Windows mshta utility against a remote URL (fixars[.]top). mshta downloads and executes arbitrary HTA/script content served by that host, giving the operator install-time remote code execution on the victim machine with no user interaction. The packages main module presents a generic LLM-client API as a cover; the actual payload is the automatically-executed install script.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 05:54 PM
analyzed
Jun 16, 2026, 05:59 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.