hardhat-set@2.21.0
Malicious code in hardhat-set (npm)
Analysis
hardhat-set@2.21.0 is a combosquat of the hardhat package that ships a pino-derived logger with an injected command-and-control beacon. On require, it collects the host's hostname, OS, username and platform and exfiltrates them as a multipart file named sysinfo.txt to hxxp://167[.]88[.]167[.]54:8085/upload, while beaconing JSON (userkey 309, host, OS, username) to hxxp://167[.]88[.]167[.]54:8087/api/notify and hxxp://167[.]88[.]167[.]54:8087/api/log. The C2 logic is hidden in a 4MB obfuscated lib/config.js (javascript-obfuscator output with hex-escaped method names). The beacon runs automatically when the package is loaded.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 05:36 PM
- analyzed
- Aug 5, 2026, 05:36 PM
Related advisories
- npm-dc-dev@1.1.1
- dolyame-boxy-mobile-bnpl-card-gallery@35.9.5
- devplatform-spa-tokens@35.3.1
- dolyame-boxy-independent-bnpl-tiles@35.7.4
- devplatform-iam-client@35.5.6
- bnpl-blocks-mobile-bnpl-floating-button@35.3.6
- devplatform-test-pvm-is-even@35.9.5
- devplatform-test-pvm-is-odd@35.3.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.