alelo-payment @99.0.2
Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 10:37 PM UTC
OSV ID
MAL-2026-14025
Ecosystem
npm
Summary
On npm install, preinstall.js collects hostname, username, platform, cwd, and the full process.env and POSTs the payload over HTTPS (with TLS verification disabled via rejectUnauthorized:false) to a hardcoded bare IP at 209.99.185.109/preinstall. A postinstall path additionally reads.env,../.env,../../.env,.npmrc, and package.json from the install directory, captures whoami/id output and the full process.env, and POSTs the bundle to 209.99.185.109/postinstall with TLS verification disabled..npmrc contains npm _authToken values and.env typically holds CI/CD secrets and cloud credentials. A bundled PowerShell artifact references publishing under npm account oxy12@proton.me and the package name and 99.0.0 version resemble a typosquat / dependency-confusion lure targeting an internal Alelo utility, with no legitimate functionality shipped.
Source: amazon-inspector (ef5aceecfb22fd66b4e0861399aa6864ba19a983f3483294dd0740e7e24d1c34)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.