LWA-2026-3956 MAL-2026-5515 ↗ confirmed malware

yelp-react-component-chaos@8.14.5

Malicious code in yelp-react-component-chaos (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.004 · Unix ShellT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

yelp-react-component-chaos is a dependency-confusion package impersonating a Yelp React component. Its preinstall.js harvests system metadata, filters process.env for TOKEN/SECRET/KEY/AUTH/NPM/AWS/GITHUB/YELP/DATABASE variables, reads sensitive credential files (.npmrc, .ssh/id_rsa, .aws/credentials, .env, .docker/config.json), enumerates non-internal network interfaces, and exfiltrates everything as a JSON POST to an interception host (3w0e8s6jg6tkyv03vdesvscvlmrdf43t[.]oastify[.]com), with a fallback that writes to /tmp/.yelp-chaos-output. The code self-labels as 'dependency-confusion-yelp'.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 03:22 PM
analyzed
Jun 10, 2026, 03:22 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.