alelo-payment@99.0.0
Malicious code in alelo-payment (npm)
Analysis
The package's preinstall and postinstall hooks (preinstall.js and index.js) collect host metadata — hostname, username, home directory, platform, architecture, cwd, and the full process environment — and POST it to 209[.]99[.]185[.]109:443 at paths /preinstall and /postinstall. The postinstall hook additionally reads the contents of .env, .npmrc, package.json, ../.env and ../../.env (up to 5000 characters each) and runs whoami and id, exfiltrating all of it to the same host. The TLS connection is made with certificate verification disabled. This steals the installer's environment variables and credential files (.npmrc, .env) and sends them to a remote server.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 11:13 PM
- analyzed
- Aug 13, 2026, 11:14 PM
Related advisories
- alelo-sdk@99.0.0
- alelo-core@99.0.0
- notafollower@1.0.0
- async-lock-queue@3.0.1
- tailwind-custom-templates@0.7.2
- try-lock-runner@3.2.1
- single-flight-lock@1.0.0
- priority-mutex-lane@2.5.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.