LWA-2026-11242 confirmed malware

alelo-payment@99.0.0

Malicious code in alelo-payment (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package's preinstall and postinstall hooks (preinstall.js and index.js) collect host metadata — hostname, username, home directory, platform, architecture, cwd, and the full process environment — and POST it to 209[.]99[.]185[.]109:443 at paths /preinstall and /postinstall. The postinstall hook additionally reads the contents of .env, .npmrc, package.json, ../.env and ../../.env (up to 5000 characters each) and runs whoami and id, exfiltrating all of it to the same host. The TLS connection is made with certificate verification disabled. This steals the installer's environment variables and credential files (.npmrc, .env) and sends them to a remote server.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 11:13 PM
analyzed
Aug 13, 2026, 11:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.