yelp-react-component-chaos@8.14.5
Malicious code in yelp-react-component-chaos (npm)
Analysis
yelp-react-component-chaos is a dependency-confusion package impersonating a Yelp React component. Its preinstall.js harvests system metadata, filters process.env for TOKEN/SECRET/KEY/AUTH/NPM/AWS/GITHUB/YELP/DATABASE variables, reads sensitive credential files (.npmrc, .ssh/id_rsa, .aws/credentials, .env, .docker/config.json), enumerates non-internal network interfaces, and exfiltrates everything as a JSON POST to an interception host (3w0e8s6jg6tkyv03vdesvscvlmrdf43t[.]oastify[.]com), with a fallback that writes to /tmp/.yelp-chaos-output. The code self-labels as 'dependency-confusion-yelp'.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 03:22 PM
- analyzed
- Jun 10, 2026, 03:22 PM
Related advisories
- optional-cpu-features@1.0.3
- css-flow-render-shim@1.0.0
- css-display-reading-polyfill@1.0.0
- simple-date-formatter-new-16@1.0.0
- internallib_v463@1.0.2
- internallib_v657@1.0.1
- @nimbsuedge3/xar@1.1.1
- @nimbusedge2/xa@1.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.