meualelo @99.0.0
Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 10:37 PM UTC
OSV ID
MAL-2026-14033
Ecosystem
npm
Summary
The package's preinstall.js collects hostname, username, platform, cwd, and the full process.env, then POSTs the JSON payload over HTTPS (with TLS verification disabled via rejectUnauthorized:false) to the hardcoded bare-IP endpoint https://209.99.185.109/preinstall. index.js (postinstall path) additionally reads.env,.npmrc, package.json, and parent-directory.env files, runs whoami/id, and ships the collected contents plus full process.env to https://209.99.185.109/postinstall..npmrc typically contains the installer's npm _authToken and.env commonly contains cloud, database, and CI credentials. The package presents itself with author 'Alelo Dev Team' at version 99.0.0 while a bundled login.ps1 references a personal proton.me account for npm publishing, consistent with brand impersonation of Alelo.
Source: amazon-inspector (6fdf84c3f49f6d13b7ccbed745056f8bf03c4c7a2b814152962361ac07bd4191)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.