LWA-2026-5949 MAL-2026-6364 ↗ confirmed malware

openllmapi@4.0.2

Malicious code in openllmapi (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.003 · Windows Command ShellT1218.005 · MshtaT1105 · Ingress Tool Transfer

Analysis

Package openllmapi@4.0.2 is a trojanized impersonation of an LLM API client. During npm install, its preinstall hook executes mshta.exe with a remote URL (hxxp://fixars[.]top), causing Windows systems to silently download and execute an arbitrary HTA payload from that domain. The main source file is a decoy boilerplate API client; the malicious behaviour is in the preinstall script only.

analyzed by
Leitwacht
first seen
Jun 24, 2026, 02:11 AM
analyzed
Jun 24, 2026, 02:11 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.