OpenSSF/OSV advisory MAL-2026-14023 confirms this npm version as malicious. The package auto-executes exfiltration code during npm install via preinstall and postinstall lifecycle scripts. preinstall.js collects the hostname, username, platform, cwd, and the full process.env, then POSTs the JSON payload to https://209.99.185.109/preinstall with TLS certificate validation disabled (rejectUnauthorized: false). index.js (postinstall) reads.env,.npmrc, package.json,../.env, and../../.env from...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in alelo-common (npm)
Details
The package auto-executes exfiltration code during npm install via preinstall and postinstall lifecycle scripts. preinstall.js collects the hostname, username, platform, cwd, and the full process.env, then POSTs the JSON payload to https://209.99.185.109/preinstall with TLS certificate validation disabled (rejectUnauthorized: false). index.js (postinstall) reads.env,.npmrc, package.json,../.env, and../../.env from the install directory, runs whoami and id, gathers process.env, and POSTs the aggregated payload to https://209.99.185.109/postinstall over the same TLS-disabled channel. The.npmrc read captures the installer's npm _authToken; the.env reads capture cloud, database, and API credentials. The destination is a bare-IP endpoint with no relationship to any legitimate publisher, and TLS verification is deliberately disabled. The package name resembles a private/internal scope, consistent with a dependency-confusion lure.
Decision reason
OpenSSF Malicious Packages via OSV confirms alelo-common@99.0.0 as malicious (MAL-2026-14023): Malicious code in alelo-common (npm)