LWA-2026-11230 confirmed malware
alelo-core@99.0.0
Malicious code in alelo-core (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel
Analysis
The package's preinstall hook (preinstall.js) collects the hostname, username, platform, working directory, and the full process environment (including any NPM_TOKEN, GITHUB_TOKEN, and cloud credentials present in the installer's environment), serializes them to JSON, and POSTs them to hxxps://209[.]99[.]185[.]109:443/preinstall with TLS certificate verification disabled. The postinstall script references an index.js that is not shipped in the package, so the install fails after the exfiltration has already occurred.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 11:09 PM
- analyzed
- Aug 13, 2026, 11:09 PM
Related advisories
- notafollower@1.0.0
- async-lock-queue@3.0.1
- tailwind-custom-templates@0.7.2
- try-lock-runner@3.2.1
- single-flight-lock@1.0.0
- priority-mutex-lane@2.5.1
- resource-lease-pool@1.4.2
- semaphore-job-pool@2.2.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.