yelp-react-component-chaos@8.14.5
Malicious code in yelp-react-component-chaos (npm)
Analysis
yelp-react-component-chaos is a dependency-confusion package impersonating a Yelp React component. Its preinstall.js harvests system metadata, filters process.env for TOKEN/SECRET/KEY/AUTH/NPM/AWS/GITHUB/YELP/DATABASE variables, reads sensitive credential files (.npmrc, .ssh/id_rsa, .aws/credentials, .env, .docker/config.json), enumerates non-internal network interfaces, and exfiltrates everything as a JSON POST to an interception host (3w0e8s6jg6tkyv03vdesvscvlmrdf43t[.]oastify[.]com), with a fallback that writes to /tmp/.yelp-chaos-output. The code self-labels as 'dependency-confusion-yelp'.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 03:22 PM
- analyzed
- Jun 10, 2026, 03:22 PM
Related advisories
- optional-cpu-features@1.0.3
- dolyame-boxy-desktop-bnpl-text-block@35.9.7
- bnpl-blocks-independent-bnpl-documents@35.6.6
- devplatform-api-v2-resources-metadata@35.7.7
- bnpl-blocks-atom-bnpl-dangerously-html@35.2.4
- internallib_v524@1.0.2
- simple-date-formatter-new-8@1.0.0
- simple-date-formatter-new-7@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.