alelo-services@99.0.0
Malicious code in alelo-services (npm)
Analysis
The package runs two install-time hooks that exfiltrate the installer's environment and credentials to a hardcoded remote host. The preinstall hook collects the hostname, username, platform, working directory and the full process environment and POSTs them to hxxps://209[.]99[.]185[.]109:443/preinstall. The postinstall hook additionally reads the installer's .npmrc, .env, package.json and parent-directory .env files (up to 5000 characters each), runs whoami and id, and POSTs all collected data to hxxps://209[.]99[.]185[.]109:443/postinstall. The .npmrc read exposes the installer's npm publish/auth token; the env dump exposes any NPM_TOKEN, GITHUB_TOKEN, cloud credentials and other secrets present in the environment.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 11:13 PM
- analyzed
- Aug 13, 2026, 11:14 PM
Related advisories
- alelo-common@99.0.0
- alelo-client@99.0.0
- alelo-payment@99.0.0
- alelo-sdk@99.0.0
- alelo-core@99.0.0
- notafollower@1.0.0
- async-lock-queue@3.0.1
- tailwind-custom-templates@0.7.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.