LWA-2026-12606 confirmed malware

hardhat-promised@2.21.0

Malicious code in hardhat-promised (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1036 · MasqueradingT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

hardhat-promised@2.21.0 ships a trojanized clone of the pino logger source tree (lib/levels.js, lib/tools.js, lib/proto.js, lib/multistream.js, docs/transports.md) under an unrelated combosquat name, with pino's small lib/config.js replaced by a 4.3 MB obfuscated payload (hex-escaped string array, rotating decoder, tens of thousands of _0x-style method wrappers). index.js requires ./lib/config at load time, so merely requiring or importing the package executes the payload — no install hook is involved. On execution it fingerprints the host and beacons it over HTTP to a hardcoded command-and-control server at 167[.]88[.]172[.]33: it POSTs JSON to /api/notify and /api/log on port 8087 (fields ukey, host, os, username, timestamp, with a custom Validation HMAC header and an axios User-Agent) and POSTs a multipart/form-data upload to /upload on port 8085 containing a generated sysinfo.txt with Host, OS, Username, Platform and Timestamp. Requests repeat on a one-second timer. IOCs: C2 167[.]88[.]172[.]33 ports 8085 and 8087; URLs hxxp://167[.]88[.]172[.]33:8087/api/notify, hxxp://167[.]88[.]172[.]33:8087/api/log, hxxp://167[.]88[.]172[.]33:8085/upload; dropped artifact sysinfo.txt.

analyzed by
Leitwacht
first seen
Oct 6, 2026, 03:01 PM
analyzed
Oct 6, 2026, 03:02 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.