LWA-2026-12587 MAL-2026-17560 ↗ confirmed malware

hardhat-spack@3.0.2

Malicious code in hardhat-spack (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1140 · Deobfuscate/Decode Files or InformationT1071.001 · Web ProtocolsT1102 · Web ServiceT1105 · Ingress Tool Transfer

Analysis

hardhat-spack@3.0.2 is a trojanized clone of the pino logger: the source tree (index.js, lib/, docs/, favicon.ico, pretty-demo.png) is copied from pino, but index.js and lib/caller.js carry an injected remote-code loader. Requiring the package runs a middleware that spawns a detached, unref'd node process (spawn("node", ["lib/caller.js", ...], {detached:true, stdio:"ignore"})) so the payload executes in the background and outlives the parent process. lib/caller.js shadows the process object with hardcoded base64 blobs and decodes them at runtime: the API key decodes to the C2 URL hxxps://iphub-encrypted[.]vercel[.]app/api/auth/f1f097d93c318c92f0c5, with the header x-secret-key: _ . It POSTs to that endpoint via axios, takes the response body, and executes it with new Function.constructor("require", s)(require), giving the fetched second stage full require() access; the request is retried up to 5 times. The same encoded constants are duplicated in lib/const.js. Any environment that installs or requires this package should be treated as compromised: the loader contacts the C2 and runs whatever code the operator returns. IOC: hxxps://iphub-encrypted[.]vercel[.]app/api/auth/f1f097d93c318c92f0c5 (header x-secret-key: _).

analyzed by
Leitwacht
first seen
Oct 4, 2026, 09:48 PM
analyzed
Oct 5, 2026, 06:26 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.