LWA-2026-11244 confirmed malware

alelo-common@99.0.0

Malicious code in alelo-common (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package runs a preinstall hook (preinstall.js) and a postinstall hook (index.js) on install. Both collect the full environment variable set — including CI/cloud credentials such as GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY, OPENAI_API_KEY, ANTHROPIC_API_KEY, STRIPE_SECRET_KEY, SLACK_TOKEN, SENDGRID_API_KEY, DIGITALOCEAN_TOKEN, and HF_TOKEN — along with hostname, username, platform, and cwd, and POST them as JSON to hxxps://209[.]99[.]185[.]109:443 at paths /preinstall and /postinstall (TLS verification disabled). The postinstall hook additionally reads the contents of .env, .npmrc, and parent-directory .env files and runs whoami/id, sending those too. All collected data is exfiltrated to the remote host on install.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 11:13 PM
analyzed
Aug 13, 2026, 11:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.