MAL-2026-14025
Dashboard / Malicious Package / MAL-2026-14025
MAL-2026-14025
Summary: Malicious code in alelo-payment (npm)
Details: Source: amazon-inspector (ef5aceecfb22fd66b4e0861399aa6864ba19a983f3483294dd0740e7e24d1c34) On npm install, preinstall.js collects hostname, username, platform, cwd, and the full process.env and POSTs the payload over HTTPS (with TLS verification disabled via rejectUnauthorized:false) to a hardcoded bare IP at 209.99.185.109/preinstall. A postinstall path additionally reads.env,../.env,../../.env,.npmrc, and package.json from the install directory, captures whoami/id output and the full process.env, and POSTs the bundle to 209.99.185.109/postinstall with TLS verification disabled..npmrc contains npm _authToken values and.env typically holds CI/CD secrets and cloud credentials. A bundled PowerShell artifact references publishing under npm account [email protected] and the package name and 99.0.0 version resemble a typosquat / dependency-confusion lure targeting an internal Alelo utility, with no legitimate functionality shipped.
References: https://www.npmjs.com/package/alelo-payment/v/99.0.2, https://www.npmjs.com/package/alelo-payment/v/99.0.0
Affected packages
Package
Name: alelo-payment
Purl: pkg:npm/alelo-payment
Affected ranges
Type: N/A
Events:
