hardhat-kex@2.0.1
Malicious code in hardhat-kex (npm)
Analysis
hardhat-kex@2.0.1 is a trojanized clone of the pino logger: the README, docs/, index.d.ts and lib/* files are copied verbatim from pino 9.6.0 (lib/meta.js still reports version 9.6.0), but the package's entry point index.js requires ./lib/config, which has been replaced with a 4.5MB javascript-obfuscator payload — a hex-escaped string array with a rotating decoder and flattened control flow, accounting for 94% of the 4.77MB tarball. The genuine pino lib/config.js is a ~200-byte constants module, so this file is an injected payload that executes as soon as the package is required or imported. The obfuscated layer hides its strings (URLs, hosts, file paths) behind the decoder, and the payload's initialization is heavy enough that requiring the package does not complete promptly. The package declares no repository, its description is an unrelated vulnerability-disclosure policy sentence, and its only runtime dependencies are axios and parse-json, which the visible code never uses. No plaintext C2 endpoint is exposed in the outer layer; the network destination is recoverable only by deobfuscating lib/config.js.
- analyzed by
- Leitwacht
- first seen
- Oct 4, 2026, 06:19 PM
- analyzed
- Oct 5, 2026, 06:29 PM
Related advisories
- hardhat-spack@3.0.2
- solidity-gas-watcher@2.21.0
- wallet-connect-adapter@1.4.2
- @insiderintelligence/componentlibrary@9.9.10
- solidity-lock@2.21.0
- envparse2@1.0.1
- chai-logger@3.0.2
- tldriver@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.