MAL-2026-14025

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/alelo-payment/MAL-2026-14025.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-14025
Aliases
  • GHSA-4whx-hjpv-g8xf
Published
2026-08-14T14:11:41Z
Modified
2026-09-24T09:30:07Z
Summary
Malicious code in alelo-payment (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (ef5aceecfb22fd66b4e0861399aa6864ba19a983f3483294dd0740e7e24d1c34)

On npm install, preinstall.js collects hostname, username, platform, cwd, and the full process.env and POSTs the payload over HTTPS (with TLS verification disabled via rejectUnauthorized:false) to a hardcoded bare IP at 209.99.185.109/preinstall. A postinstall path additionally reads.env,../.env,../../.env,.npmrc, and package.json from the install directory, captures whoami/id output and the full process.env, and POSTs the bundle to 209.99.185.109/postinstall with TLS verification disabled..npmrc contains npm _authToken values and.env typically holds CI/CD secrets and cloud credentials. A bundled PowerShell artifact references publishing under npm account oxy12@proton.me and the package name and 99.0.0 version resemble a typosquat / dependency-confusion lure targeting an internal Alelo utility, with no legitimate functionality shipped.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-017757",
            "import_time":  "2026-08-14T14:28:06.376910956Z",
            "modified_time":  "2026-08-14T14:11:41Z",
            "sha256":  "43320a7e68c63b6272ce891892270531d86018bcdc95584f461b0f97ddd15997",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.2"
            ]
        },
        {
            "id":  "IN-MAL-2026-017774",
            "import_time":  "2026-08-14T14:28:08.072080798Z",
            "modified_time":  "2026-08-14T14:14:11Z",
            "sha256":  "ef5aceecfb22fd66b4e0861399aa6864ba19a983f3483294dd0740e7e24d1c34",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.0"
            ]
        },
        {
            "id":  "RLMA-2026-10686",
            "import_time":  "2026-09-24T09:21:32.373796546Z",
            "modified_time":  "2026-09-22T17:16:19Z",
            "sha256":  "89fdda8d1f17a7ed408f05598830968ba7e947afb70ff24853d71a5266394818",
            "source":  "reversing-labs",
            "versions":  [
                "99.0.0",
                "99.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / alelo-payment

Package

Name
alelo-payment
View open source insights on deps.dev
Purl
pkg:npm/alelo-payment

Affected ranges

Affected versions

99.*
99.0.0
99.0.2

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "preinstall.js",
            "sha256":  "b37206713fc25fedb6193f5d1ac2eecf834e826eed4c03b3bc570385a554e28d",
            "tlsh":  "b0f084f491a9eab02e7857c0e09aa40296b3e1113b277cf4a9e90249678d1e41172cf6"
        },
        {
            "path":  "index.js",
            "sha256":  "70a8739590ceacd616e00eef3ccbe975d174c5cf731addb93da8eb7ad8a2fd5f",
            "tlsh":  "4311abf452a5b3b06ab556c4e5ee50016263e2023e27b5f0b9ec02556b499b805b3df4"
        },
        {
            "path":  "login.ps1",
            "sha256":  "d784a3de392836730544da8e2ba25bcaaad2632f0cc8e4b8ce76b5cb4fe82d2b",
            "tlsh":  "d7f0a272910a614d3ee4466b00f4f536fd3b133269d4de94a6a916c9f8c195c2972833"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "alelo-payment-99.0.2.tgz",
            "hashes":  {
                "sha1":  "212fad2fac352e80975b99218d2c1b04af3fc65e",
                "sha512_sri":  "sha512-1H6fNywNfJmJ1RpQLMYnk3MJTqSJ7eJnxSY3pBVAyCCc8LvgP47AWpLgL7Ow+dlXRa71fQxgJJg/jeMxDCurWw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/alelo-payment/MAL-2026-14025.json"