alelo-api@99.0.2
Malicious code in alelo-api (npm)
Analysis
The package's preinstall and postinstall hooks (preinstall.js and index.js) harvest the entire process environment and POST it as JSON to the remote capture host alelo1786663101[.]requestcatcher[.]com at paths /preinstall and /postinstall. The exfiltrated data includes all credential-bearing environment variables present at install time: GITHUB_TOKEN, GH_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, OPENAI_API_KEY, ANTHROPIC_API_KEY, STRIPE_SECRET_KEY, SLACK_TOKEN, TWILIO_AUTH_TOKEN, HF_TOKEN, DIGITALOCEAN_TOKEN, CLOUDFLARE_API_TOKEN, NETLIFY_AUTH_TOKEN, GITLAB_TOKEN, CI_JOB_TOKEN, CARGO_REGISTRY_TOKEN, PYPI_TOKEN, SENDGRID_API_KEY, and DOCKER_PASSWORD, along with hostname, username, working directory, and platform. The postinstall hook additionally reports the contents of files in the install directory and the current user. The exfiltration occurs automatically on package install.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 11:19 PM
- analyzed
- Aug 13, 2026, 11:21 PM
Related advisories
- alelo-utils@99.0.0
- alelo-services@99.0.0
- alelo-common@99.0.0
- alelo-client@99.0.0
- alelo-payment@99.0.0
- alelo-sdk@99.0.0
- alelo-core@99.0.0
- notafollower@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.