hardhat-promised@2.21.0
Malicious code in hardhat-promised (npm)
Analysis
hardhat-promised@2.21.0 ships a trojanized clone of the pino logger source tree (lib/levels.js, lib/tools.js, lib/proto.js, lib/multistream.js, docs/transports.md) under an unrelated combosquat name, with pino's small lib/config.js replaced by a 4.3 MB obfuscated payload (hex-escaped string array, rotating decoder, tens of thousands of _0x-style method wrappers). index.js requires ./lib/config at load time, so merely requiring or importing the package executes the payload — no install hook is involved. On execution it fingerprints the host and beacons it over HTTP to a hardcoded command-and-control server at 167[.]88[.]172[.]33: it POSTs JSON to /api/notify and /api/log on port 8087 (fields ukey, host, os, username, timestamp, with a custom Validation HMAC header and an axios User-Agent) and POSTs a multipart/form-data upload to /upload on port 8085 containing a generated sysinfo.txt with Host, OS, Username, Platform and Timestamp. Requests repeat on a one-second timer. IOCs: C2 167[.]88[.]172[.]33 ports 8085 and 8087; URLs hxxp://167[.]88[.]172[.]33:8087/api/notify, hxxp://167[.]88[.]172[.]33:8087/api/log, hxxp://167[.]88[.]172[.]33:8085/upload; dropped artifact sysinfo.txt.
- analyzed by
- Leitwacht
- first seen
- Oct 6, 2026, 03:01 PM
- analyzed
- Oct 6, 2026, 03:02 PM
Related advisories
- @pinecone-experience/messages@99.9.1
- solidity-gas-watcher@2.21.0
- nebulaai-sdk@1.0.0
- envparse2@1.0.1
- @shared-web/assets@9.9.10
- sbironman@1.0.0
- ded-aa-common-ded-aa-common-core@35.1.6
- bnpl-blocks-independent-bnpl-open-api@35.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.