MAL-2026-14033
Malicious code in meualelo (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (6fdf84c3f49f6d13b7ccbed745056f8bf03c4c7a2b814152962361ac07bd4191) The package's preinstall.js collects hostname, username, platform, cwd, and the full process.env, then POSTs the JSON payload over HTTPS (with TLS verification disabled via rejectUnauthorized:false) to the hardcoded bare-IP endpoint https://209.99.185.109/preinstall. index.js (postinstall path) additionally reads.env,.npmrc, package.json, and parent-directory.env files, runs whoami/id, and ships the collected contents plus full process.env to https://209.99.185.109/postinstall..npmrc typically contains the installer's npm _authToken and.env commonly contains cloud, database, and CI credentials. The package presents itself with author 'Alelo Dev Team' at version 99.0.0 while a bundled login.ps1 references a personal proton.me account for npm publishing, consistent with brand impersonation of Alelo.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for meualelo (npm). Pin to a known-safe version or switch to an alternative.