MAL-2026-14025Malicious code in alelo-payment (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | alelo-payment | 99.0.0 |
| npm | alelo-payment | 99.0.2 |
{"modified":"2026-08-14T14:29:59Z","published":"2026-08-14T14:11:41Z","schema_version":"1.7.4","id":"MAL-2026-14025","summary":"Malicious code in alelo-payment (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ef5aceecfb22fd66b4e0861399aa6864ba19a983f3483294dd0740e7e24d1c34)\nOn npm install, preinstall.js collects hostname, username, platform, cwd, and the full process.env and POSTs the payload over HTTPS (with TLS verification disabled via rejectUnauthorized:false) to a hardcoded bare IP at 209.99.185.109/preinstall. A postinstall path additionally reads.env,../.env,../../.env,.npmrc, and package.json from the install directory, captures whoami/id output and the full process.env, and POSTs the bundle to 209.99.185.109/postinstall with TLS verification disabled..npmrc contains npm _authToken values and.env typically holds CI/CD secrets and cloud credentials. A bundled PowerShell artifact references publishing under npm account oxy12@proton.me and the package name and 99.0.0 version resemble a typosquat / dependency-confusion lure targeting an internal Alelo utility, with no legitimate functionality shipped.\n","affected":[{"package":{"ecosystem":"npm","name":"alelo-payment"},"versions":["99.0.2","99.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"preinstall.js","sha256":"b37206713fc25fedb6193f5d1ac2eecf834e826eed4c03b3bc570385a554e28d","tlsh":"b0f084f491a9eab02e7857c0e09aa40296b3e1113b277cf4a9e90249678d1e41172cf6"},{"path":"index.js","sha256":"70a8739590ceacd616e00eef3ccbe975d174c5cf731addb93da8eb7ad8a2fd5f","tlsh":"4311abf452a5b3b06ab556c4e5ee50016263e2023e27b5f0b9ec02556b499b805b3df4"},{"path":"login.ps1","sha256":"d784a3de392836730544da8e2ba25bcaaad2632f0cc8e4b8ce76b5cb4fe82d2b","tlsh":"d7f0a272910a614d3ee4466b00f4f536fd3b133269d4de94a6a916c9f8c195c2972833"}],"package_integrity":[{"filename":"alelo-payment-99.0.2.tgz","hashes":{"sha1":"212fad2fac352e80975b99218d2c1b04af3fc65e","sha512_sri":"sha512-1H6fNywNfJmJ1RpQLMYnk3MJTqSJ7eJnxSY3pBVAyCCc8LvgP47AWpLgL7Ow+dlXRa71fQxgJJg/jeMxDCurWw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/alelo-payment/v/99.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/alelo-payment/v/99.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017757","import_time":"2026-08-14T14:28:06.376910956Z","modified_time":"2026-08-14T14:11:41Z","sha256":"43320a7e68c63b6272ce891892270531d86018bcdc95584f461b0f97ddd15997","source":"amazon-inspector","versions":["99.0.2"]},{"id":"IN-MAL-2026-017774","import_time":"2026-08-14T14:28:08.072080798Z","modified_time":"2026-08-14T14:14:11Z","sha256":"ef5aceecfb22fd66b4e0861399aa6864ba19a983f3483294dd0740e7e24d1c34","source":"amazon-inspector","versions":["99.0.0"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0