MAL-2026-14033
Dashboard / Malicious Package / MAL-2026-14033
MAL-2026-14033
Summary: Malicious code in meualelo (npm)
Details: Source: amazon-inspector (6fdf84c3f49f6d13b7ccbed745056f8bf03c4c7a2b814152962361ac07bd4191) The package's preinstall.js collects hostname, username, platform, cwd, and the full process.env, then POSTs the JSON payload over HTTPS (with TLS verification disabled via rejectUnauthorized:false) to the hardcoded bare-IP endpoint https://209.99.185.109/preinstall. index.js (postinstall path) additionally reads.env,.npmrc, package.json, and parent-directory.env files, runs whoami/id, and ships the collected contents plus full process.env to https://209.99.185.109/postinstall..npmrc typically contains the installer's npm _authToken and.env commonly contains cloud, database, and CI credentials. The package presents itself with author 'Alelo Dev Team' at version 99.0.0 while a bundled login.ps1 references a personal proton.me account for npm publishing, consistent with brand impersonation of Alelo.
References: https://www.npmjs.com/package/meualelo/v/99.0.0
Affected packages
Package
Name: meualelo
Purl: pkg:npm/meualelo
Affected ranges
Type: N/A
Events:
