LWA-2026-11241 confirmed malware

alelo-sdk@99.0.0

Malicious code in alelo-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

alelo-sdk@99.0.0 runs two install-time hooks that exfiltrate host data and credentials to a hardcoded server. The preinstall hook POSTs the hostname, username, platform, working directory, and the full process environment (including any NPM_TOKEN/GITHUB_TOKEN and other secrets) to hxxps://209[.]99[.]185[.]109:443/preinstall. The postinstall hook additionally reads the contents of .env, .npmrc, and package.json files (including parent-directory variants, up to 5000 characters each), runs whoami and id, and POSTs all collected data to hxxps://209[.]99[.]185[.]109:443/postinstall. Both requests use HTTPS with certificate verification disabled. The package is a fresh "internal SDK" name published at version 99.0.0.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 11:12 PM
analyzed
Aug 13, 2026, 11:12 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.