hardhat-devkit@2.3.6
Malicious code in hardhat-devkit (npm)
Analysis
hardhat-devkit@2.3.6 is a trojanized clone of the pino logging library. The package ships pino's documentation and type definitions verbatim but replaces lib/config.js — which is loaded when the package is required — with a 4MB obfuscated JavaScript payload (custom string-decoder and array-shuffle bootstrap). The entry point index.js additionally imports child_process.spawn and its exported middleware is a stub that triggers a background process. The package name impersonates the hardhat Ethereum development framework. The obfuscated payload's full behaviour is concealed by the obfuscation.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 09:52 PM
- analyzed
- Sep 17, 2026, 09:52 PM
Related advisories
- tailwindcss-form@0.5.1
- chai-as-crack@7.0.5
- @biz44/id44-client@1.1.44
- tailwind-form-kit@0.6.2
- shaon-video-downloader@1.0.2
- node-helper@1.5.4
- date-fns-formatter@1.3.8
- tailwind-scrollbar-styles@4.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.