Malicious code in alelo-payment (npm)
The alelo-payment npm package versions 99.0.0 and 99.0.2 contain malicious code that exfiltrates sensitive environment data during installation. The preinstall script collects system information and environment variables, sending them to a hardcoded IP address with TLS verification disabled. The postinstall script further reads sensitive files such as .env and .npmrc, capturing authentication tokens and secrets, and sends this data to the same remote server. The package appears to be a typosquatting or dependency confusion attempt targeting an internal Alelo utility, with no legitimate functionality.
AI Analysis
Technical Summary
The alelo-payment npm package (versions 99.0.0 and 99.0.2) includes malicious preinstall and postinstall scripts that collect and exfiltrate sensitive data from the host environment. The preinstall.js script gathers hostname, username, platform, current working directory, and the full process environment variables, then sends this information via HTTPS POST to a hardcoded IP address (209.99.185.109) with TLS verification disabled (rejectUnauthorized:false). The postinstall script reads sensitive configuration files (.env, .npmrc, package.json) and executes commands like whoami/id to gather user identity information, then sends this combined data to the same IP address. The .npmrc file may contain npm authentication tokens, and .env files often hold CI/CD secrets and cloud credentials, making this exfiltration highly sensitive. A bundled PowerShell artifact references publishing under the npm account [email protected]. The package versioning and naming suggest it is a malicious typosquat or dependency confusion lure without legitimate functionality.
Potential Impact
This malicious package can lead to the exposure of sensitive environment variables, authentication tokens, CI/CD secrets, and cloud credentials from the victim's environment. The attacker can use this stolen information to compromise systems, escalate privileges, or access cloud resources. The disabled TLS verification increases the risk of interception or manipulation during data exfiltration. Since the package has no legitimate functionality, its presence indicates a supply chain compromise or targeted attack vector.
Mitigation Recommendations
No official patch or remediation is available as this is a malicious package rather than a vulnerability in legitimate software. Users should avoid installing alelo-payment versions 99.0.0 and 99.0.2. Remove any installations of this package immediately and revoke any potentially exposed credentials or tokens. Review npm dependencies for typosquatting or dependency confusion risks. Monitor for suspicious network activity to the IP address 209.99.185.109 and block it if possible. Employ strict controls on package sources and use package integrity verification mechanisms.
Malicious code in alelo-payment (npm)
Description
The alelo-payment npm package versions 99.0.0 and 99.0.2 contain malicious code that exfiltrates sensitive environment data during installation. The preinstall script collects system information and environment variables, sending them to a hardcoded IP address with TLS verification disabled. The postinstall script further reads sensitive files such as .env and .npmrc, capturing authentication tokens and secrets, and sends this data to the same remote server. The package appears to be a typosquatting or dependency confusion attempt targeting an internal Alelo utility, with no legitimate functionality.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The alelo-payment npm package (versions 99.0.0 and 99.0.2) includes malicious preinstall and postinstall scripts that collect and exfiltrate sensitive data from the host environment. The preinstall.js script gathers hostname, username, platform, current working directory, and the full process environment variables, then sends this information via HTTPS POST to a hardcoded IP address (209.99.185.109) with TLS verification disabled (rejectUnauthorized:false). The postinstall script reads sensitive configuration files (.env, .npmrc, package.json) and executes commands like whoami/id to gather user identity information, then sends this combined data to the same IP address. The .npmrc file may contain npm authentication tokens, and .env files often hold CI/CD secrets and cloud credentials, making this exfiltration highly sensitive. A bundled PowerShell artifact references publishing under the npm account [email protected]. The package versioning and naming suggest it is a malicious typosquat or dependency confusion lure without legitimate functionality.
Potential Impact
This malicious package can lead to the exposure of sensitive environment variables, authentication tokens, CI/CD secrets, and cloud credentials from the victim's environment. The attacker can use this stolen information to compromise systems, escalate privileges, or access cloud resources. The disabled TLS verification increases the risk of interception or manipulation during data exfiltration. Since the package has no legitimate functionality, its presence indicates a supply chain compromise or targeted attack vector.
Mitigation Recommendations
No official patch or remediation is available as this is a malicious package rather than a vulnerability in legitimate software. Users should avoid installing alelo-payment versions 99.0.0 and 99.0.2. Remove any installations of this package immediately and revoke any potentially exposed credentials or tokens. Review npm dependencies for typosquatting or dependency confusion risks. Monitor for suspicious network activity to the IP address 209.99.185.109 and block it if possible. Employ strict controls on package sources and use package integrity verification mechanisms.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14025
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7f43f1bf8831d5395d771e
Added to database: 08/14/2026, 16:36:01 UTC
Last enriched: 08/14/2026, 16:51:24 UTC
Last updated: 08/14/2026, 16:51:24 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.