LWA-2026-12643 confirmed malware

hardhat-deep@2.0.1

Malicious code in hardhat-deep (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

hardhat-deep@2.0.1 is a trojanized clone of the pino logging library: it ships pino's source tree, README and docs under its own name, but replaces lib/config.js — required by the package's main entry point index.js — with a 4.5 MB javascript-obfuscator payload (hex-escaped string array, _0x identifiers, control-flow flattening) that executes as soon as the package is required. The payload fingerprints the host (hostname, OS, username, platform) and beacons over HTTP to a hardcoded command-and-control server at 167[.]88[.]172[.]33: it POSTs JSON telemetry to hxxp://167[.]88[.]172[.]33:8087/api/log and hxxp://167[.]88[.]172[.]33:8087/api/notify (body includes a user key, host name, OS string and username), and uploads a generated sysinfo.txt file via multipart POST to hxxp://167[.]88[.]172[.]33:8085/upload. Requests are sent with axios and carry custom Userkey, T and Validation headers; beacons are staggered with setTimeout delays of up to 30 seconds. The package declares axios as a runtime dependency solely to carry this traffic and provides no logging functionality. Its metadata is copied from unrelated projects (the description is taken from a vulnerability-management policy document, the bugs URL points to jsonspack[.]com, and there is no repository field).

analyzed by
Leitwacht
first seen
Oct 7, 2026, 09:36 AM
analyzed
Oct 7, 2026, 09:37 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.