alelo-utils@99.0.0
Malicious code in alelo-utils (npm)
Analysis
alelo-utils@99.0.0 runs two lifecycle hooks on install. The preinstall hook (preinstall.js) and postinstall hook (index.js) collect the hostname, username, home directory, platform, architecture, working directory, the full process environment (including any NPM_TOKEN, GITHUB_TOKEN, and other credentials), and read the contents of .env, .npmrc, and package.json files (up to 5000 characters each), plus the output of whoami and id. All collected data is POSTed as JSON over HTTPS to 209[.]99[.]185[.]109:443 at the /preinstall and /postinstall paths, with TLS certificate verification disabled. The package is a fresh high-version (99.0.0) publish with no legitimate utility functionality.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 11:13 PM
- analyzed
- Aug 13, 2026, 11:14 PM
Related advisories
- alelo-services@99.0.0
- alelo-common@99.0.0
- alelo-client@99.0.0
- alelo-payment@99.0.0
- alelo-sdk@99.0.0
- alelo-core@99.0.0
- notafollower@1.0.0
- async-lock-queue@3.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.