LWA-2026-11246 confirmed malware

alelo-utils@99.0.0

Malicious code in alelo-utils (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

alelo-utils@99.0.0 runs two lifecycle hooks on install. The preinstall hook (preinstall.js) and postinstall hook (index.js) collect the hostname, username, home directory, platform, architecture, working directory, the full process environment (including any NPM_TOKEN, GITHUB_TOKEN, and other credentials), and read the contents of .env, .npmrc, and package.json files (up to 5000 characters each), plus the output of whoami and id. All collected data is POSTed as JSON over HTTPS to 209[.]99[.]185[.]109:443 at the /preinstall and /postinstall paths, with TLS certificate verification disabled. The package is a fresh high-version (99.0.0) publish with no legitimate utility functionality.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 11:13 PM
analyzed
Aug 13, 2026, 11:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.