hardhat-base@2.2.0
Malicious code in hardhat-base (npm)
Analysis
hardhat-base@2.2.0 ships a detached background subprocess (index.js spawns `node lib/caller.js` with detached:true and unref) that fetches remote code and executes it. lib/caller.js decodes base64 constants to build the URL hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/f1f097d93c318c92f0c5, sends a GET with header `x-secret-key: _`, takes the response's `cookie` field, and runs it through the Function constructor with `require` in scope — executing arbitrary attacker-supplied code with full Node module access. The payload retries up to 5 times on failure. The package name impersonates the hardhat Ethereum development framework.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 03:20 AM
- analyzed
- Sep 14, 2026, 03:21 AM
Related advisories
- fast-xml-tagger@1.1.0
- id79-client@1.1.79
- noblox-asset.js@7.4.1
- @biz44/id99-client@1.1.100
- @biz44/id95-client@1.1.96
- @biz44/id79-client@1.1.80
- @biz44/id44-client@1.1.44
- @biz44/id12-client@1.1.13
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.