VDB
KO

MAL-2026-14033

Malicious code in meualelo (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6fdf84c3f49f6d13b7ccbed745056f8bf03c4c7a2b814152962361ac07bd4191) The package's preinstall.js collects hostname, username, platform, cwd, and the full process.env, then POSTs the JSON payload over HTTPS (with TLS verification disabled via rejectUnauthorized:false) to the hardcoded bare-IP endpoint https://209.99.185.109/preinstall. index.js (postinstall path) additionally reads.env,.npmrc, package.json, and parent-directory.env files, runs whoami/id, and ships the collected contents plus full process.env to https://209.99.185.109/postinstall..npmrc typically contains the installer's npm _authToken and.env commonly contains cloud, database, and CI credentials. The package presents itself with author 'Alelo Dev Team' at version 99.0.0 while a bundled login.ps1 references a personal proton.me account for npm publishing, consistent with brand impersonation of Alelo.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / meualelo

No fixed version published yet for meualelo (npm). Pin to a known-safe version or switch to an alternative.

References