LWA-2026-10544 MAL-2026-13609 ↗ confirmed malware

hardhat-set@2.21.0

Malicious code in hardhat-set (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1027 · Obfuscated Files or Information

Analysis

hardhat-set@2.21.0 is a combosquat of the hardhat package that ships a pino-derived logger with an injected command-and-control beacon. On require, it collects the host's hostname, OS, username and platform and exfiltrates them as a multipart file named sysinfo.txt to hxxp://167[.]88[.]167[.]54:8085/upload, while beaconing JSON (userkey 309, host, OS, username) to hxxp://167[.]88[.]167[.]54:8087/api/notify and hxxp://167[.]88[.]167[.]54:8087/api/log. The C2 logic is hidden in a 4MB obfuscated lib/config.js (javascript-obfuscator output with hex-escaped method names). The beacon runs automatically when the package is loaded.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 05:36 PM
analyzed
Aug 5, 2026, 05:36 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.