LWA-2026-11247 confirmed malware

alelo-api@99.0.2

Malicious code in alelo-api (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall and postinstall hooks (preinstall.js and index.js) harvest the entire process environment and POST it as JSON to the remote capture host alelo1786663101[.]requestcatcher[.]com at paths /preinstall and /postinstall. The exfiltrated data includes all credential-bearing environment variables present at install time: GITHUB_TOKEN, GH_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, OPENAI_API_KEY, ANTHROPIC_API_KEY, STRIPE_SECRET_KEY, SLACK_TOKEN, TWILIO_AUTH_TOKEN, HF_TOKEN, DIGITALOCEAN_TOKEN, CLOUDFLARE_API_TOKEN, NETLIFY_AUTH_TOKEN, GITLAB_TOKEN, CI_JOB_TOKEN, CARGO_REGISTRY_TOKEN, PYPI_TOKEN, SENDGRID_API_KEY, and DOCKER_PASSWORD, along with hostname, username, working directory, and platform. The postinstall hook additionally reports the contents of files in the install directory and the current user. The exfiltration occurs automatically on package install.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 11:19 PM
analyzed
Aug 13, 2026, 11:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.