LWA-2026-12090 MAL-2026-16348 ↗ confirmed malware

hardhat-base@2.2.0

Malicious code in hardhat-base (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

hardhat-base@2.2.0 ships a detached background subprocess (index.js spawns `node lib/caller.js` with detached:true and unref) that fetches remote code and executes it. lib/caller.js decodes base64 constants to build the URL hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/f1f097d93c318c92f0c5, sends a GET with header `x-secret-key: _`, takes the response's `cookie` field, and runs it through the Function constructor with `require` in scope — executing arbitrary attacker-supplied code with full Node module access. The payload retries up to 5 times on failure. The package name impersonates the hardhat Ethereum development framework.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 03:20 AM
analyzed
Sep 14, 2026, 03:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.