aillmgen@4.0.2
Malicious code in aillmgen (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
On installation, this package runs a preinstall hook that shells out to the Windows mshta utility against a remote URL (fixars[.]top). mshta downloads and executes arbitrary HTA/script content served by that host, giving the operator install-time remote code execution on the victim machine with no user interaction. The packages main module presents a generic LLM-client API as a cover; the actual payload is the automatically-executed install script.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 05:54 PM
- analyzed
- Jun 16, 2026, 05:59 PM
Related advisories
- chai-plugin-kit@5.8.1
- easyllmai@3.0.1
- ssr-auth-sync@1.6.16
- zgmiai-claude-code@1.0.56
- zetrix-development-utils@1.0.2
- chai-plugin-helper@1.7.3
- nat-ulid@3.0.2
- your-unique-package-name1@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.