LWA-2026-12216 MAL-2026-16349 ↗ confirmed malware

hardhat-devkit@2.3.6

Malicious code in hardhat-devkit (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or Information

Analysis

hardhat-devkit@2.3.6 is a trojanized clone of the pino logging library. The package ships pino's documentation and type definitions verbatim but replaces lib/config.js — which is loaded when the package is required — with a 4MB obfuscated JavaScript payload (custom string-decoder and array-shuffle bootstrap). The entry point index.js additionally imports child_process.spawn and its exported middleware is a stub that triggers a background process. The package name impersonates the hardhat Ethereum development framework. The obfuscated payload's full behaviour is concealed by the obfuscation.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 09:52 PM
analyzed
Sep 17, 2026, 09:52 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.