LWA-2026-6712 MAL-2026-10461 ↗ confirmed malware

gptlite@4.0.8

Malicious code in gptlite (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package gptlite@4.0.8 is a trojanized AI API wrapper. Its preinstall hook (preinstall.js) runs `mshta hxxp://fixars[.]top` on Windows, which fetches and executes arbitrary script from the remote host fixars[.]top. The main module (gptlite.js) appears to be a legitimate GPTMiniClient library, but the install-time hook performs remote code execution without the installer's knowledge or consent.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 03:21 PM
analyzed
Jul 13, 2026, 03:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.