gptlite@4.0.8
Malicious code in gptlite (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
The package gptlite@4.0.8 is a trojanized AI API wrapper. Its preinstall hook (preinstall.js) runs `mshta hxxp://fixars[.]top` on Windows, which fetches and executes arbitrary script from the remote host fixars[.]top. The main module (gptlite.js) appears to be a legitimate GPTMiniClient library, but the install-time hook performs remote code execution without the installer's knowledge or consent.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 03:21 PM
- analyzed
- Jul 13, 2026, 03:21 PM
Related advisories
- datavaultx@1.7.1
- auth-gen-next@1.7.13
- node-sysmon-native@1.0.0
- @sof-assistant-fe-lib/vertical-faqs@99.9.1
- font-hub@1.5.2
- remarkable-table@2.4.11
- react-markable-table@2.4.10
- markdown-editable-table@2.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.