LWA-2026-11230 confirmed malware

alelo-core@99.0.0

Malicious code in alelo-core (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook (preinstall.js) collects the hostname, username, platform, working directory, and the full process environment (including any NPM_TOKEN, GITHUB_TOKEN, and cloud credentials present in the installer's environment), serializes them to JSON, and POSTs them to hxxps://209[.]99[.]185[.]109:443/preinstall with TLS certificate verification disabled. The postinstall script references an index.js that is not shipped in the package, so the install fails after the exfiltration has already occurred.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 11:09 PM
analyzed
Aug 13, 2026, 11:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.