hardhat-core@2.1.2
Malicious code in hardhat-core (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1195.002 · Compromise Software Supply Chain
Analysis
hardhat-core is a combosquat of the hardhat Ethereum framework that ships a pino-style logger codebase with an injected remote-code-execution dropper. index.js spawns lib/caller.js as a detached background node process (stdio ignored, parent unref'd). caller.js POSTs to hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/f1f097d93c318c92f0c5 with the header x-secret-key: _, receives a JavaScript payload in the response, and executes it via the Function constructor with full require access — fetching and running arbitrary remote code at runtime.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 12:50 AM
- analyzed
- Sep 17, 2026, 12:50 AM
Related advisories
- laycot@1.3.10
- tailwindcss-contact-form@0.5.1
- tailwindcss-form@0.5.1
- farplotzy@0.1.0
- farplotx@1.0.1
- ausitool@1.0.1
- process-mite@1.1.79
- element-plus-vite-cli@2.9.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.