alelo-auth@99.0.2
Malicious code in alelo-auth (npm)
Analysis
The package's preinstall and postinstall hooks (preinstall.js and index.js) exfiltrate the full process environment to the request-capture host alelo1786663101[.]requestcatcher[.]com, POSTing JSON to /preinstall and /postinstall. The stolen payload includes the installer's credentials — GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, OPENAI_API_KEY, ANTHROPIC_API_KEY, STRIPE_SECRET_KEY, SLACK_TOKEN, TWILIO_AUTH_TOKEN, SENDGRID_API_KEY, HF_TOKEN, DIGITALOCEAN_TOKEN, CLOUDFLARE_API_TOKEN, NETLIFY_AUTH_TOKEN, VERCEL_TOKEN, GITLAB_TOKEN, CI_JOB_TOKEN, CI_REGISTRY_PASSWORD, DOCKER_PASSWORD, PYPI_TOKEN, CARGO_REGISTRY_TOKEN — along with hostname, username, platform, and working directory. requestcatcher[.]com is a request-capture (oast-style) service, so the collected credentials are delivered to the attacker. The exfiltration runs automatically on npm install via the lifecycle hooks.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 11:19 PM
- analyzed
- Aug 13, 2026, 11:22 PM
Related advisories
- alelo-api@99.0.2
- alelo-utils@99.0.0
- alelo-services@99.0.0
- alelo-common@99.0.0
- alelo-client@99.0.0
- alelo-payment@99.0.0
- alelo-sdk@99.0.0
- alelo-core@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.