solidity-lock@2.21.0
Malicious code in solidity-lock (npm)
Analysis
solidity-lock@2.21.0 is a trojanized clone of the pino logging library: it ships pino's source tree verbatim under an unrelated package name, with a 4MB obfuscated file lib/config.js injected as the payload. The package's main entry (index.js) requires lib/config, so loading the package executes the obfuscated code. lib/config.js is javascript-obfuscator output: a large hex-escaped string array with a custom decoder and thousands of _0x-style identifiers and escaped method references, making its runtime behaviour unreadable. The obfuscated payload's network destinations and actions could not be recovered from the encoded strings; the staging mechanism is a require-time executed obfuscated module bundled inside a cloned logging package.
- analyzed by
- Leitwacht
- first seen
- Sep 23, 2026, 06:06 PM
- analyzed
- Sep 23, 2026, 06:09 PM
Related advisories
- envparse2@1.0.1
- chai-logger@3.0.2
- tldriver@0.0.1
- lynxog@4.0.0
- ndmcjcxiebysfdb@1.0.0
- testmgkregme@1.0.1
- @shared-web/assets@9.9.10
- tailwind-form-styles@0.5.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.