alelo-common@99.0.0
Malicious code in alelo-common (npm)
Analysis
The package runs a preinstall hook (preinstall.js) and a postinstall hook (index.js) on install. Both collect the full environment variable set — including CI/cloud credentials such as GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY, OPENAI_API_KEY, ANTHROPIC_API_KEY, STRIPE_SECRET_KEY, SLACK_TOKEN, SENDGRID_API_KEY, DIGITALOCEAN_TOKEN, and HF_TOKEN — along with hostname, username, platform, and cwd, and POST them as JSON to hxxps://209[.]99[.]185[.]109:443 at paths /preinstall and /postinstall (TLS verification disabled). The postinstall hook additionally reads the contents of .env, .npmrc, and parent-directory .env files and runs whoami/id, sending those too. All collected data is exfiltrated to the remote host on install.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 11:13 PM
- analyzed
- Aug 13, 2026, 11:14 PM
Related advisories
- debug-proxy-chrome-devtools@1.0.2
- developer-dashboard@1.0.2
- passkeys-react@1.0.1
- camelot-ammv2-periphery@1.0.0
- @aerodrome-finance/contracts@1.0.0
- global-intel@1.0.1
- @fedfub/string-utils@1.0.0
- dojo-rn-interview@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.