@yeaft/webchat-agentnpm
@yeaft/webchat-agent is a confirmed malicious npm package (MAL-2026-10723) that opens a backdoor for remote access (malicious versions 1.0.171, 1.0.172, 1.0.173…). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in @yeaft/webchat-agent (npm)
What this malware does
The package installs itself as a user-level service (systemd on Linux via service/linux.js, with launchd/PM2 siblings) and, at agent startup, opens a WebSocket to a configured serverUrl (default ws://localhost:3456, overridable via SERVER_URL/config). The WebSocket message router in connection/message-router.js dispatches server-sent frames: terminal_create spawns the user's login shell via node-pty (terminal.js: pty.spawn(shell,...)) in the agent's workDir, and terminal_input writes the server's msg.data bytes directly into that PTY, giving whoever controls the server (or an attacker holding AGENT_SECRET / positioned to MITM the WebSocket) an interactive shell as the installing user. An upgrade_agent message handled by connection/upgrade.js runs npm install @yeaft/webchat-agent@latest --registry=https://pkg.yeaft.com/ and spawns a detached script that stops the service, installs the new version, and restarts it, so the remote party can also swap the agent's own code on demand from a publisher-controlled registry. On every startup, index.js additionally git-clones https://github.com/yeaft/yeaft-skills.git from the mutable main branch into ~/.claude/plugins/marketplaces/yeaft-skills-dev, chmod 0755 the hook scripts, and writes the plugin as enabled into ~/.claude/settings.json, giving whoever controls that repo the ability to land executable Claude plugin hooks on the next agent boot. The service/linux.js unit also prepends ~/.local/bin and ~/.npm-global/bin to PATH in the service environment. The remote-shell and self-upgrade paths are the package's advertised remote-agent purpose, but by threat-model definition a network-source-to-spawned-PTY dataflow on the installer's host is a backdoor, and the blast radius is full-host code execution as the installing user.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Backdoor / remote accessFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @yeaft/webchat-agent (147 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @yeaft/webchat-agent across your stack and pipelines.
If you installed it — respond
@yeaft/webchat-agent establishes remote access, so treat any host that installed it as fully compromised. Isolate the machine, remove the package, rotate all credentials it could reach, and rebuild from a trusted image rather than cleaning in place — a backdoor may have planted additional persistence.
Did it already run?
If @yeaft/webchat-agent was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks @yeaft/webchat-agent before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks @yeaft/webchat-agent-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the C2 callback and severs the channel.