hardhat-deep@2.0.1
Malicious code in hardhat-deep (npm)
Analysis
hardhat-deep@2.0.1 is a trojanized clone of the pino logging library: it ships pino's source tree, README and docs under its own name, but replaces lib/config.js — required by the package's main entry point index.js — with a 4.5 MB javascript-obfuscator payload (hex-escaped string array, _0x identifiers, control-flow flattening) that executes as soon as the package is required. The payload fingerprints the host (hostname, OS, username, platform) and beacons over HTTP to a hardcoded command-and-control server at 167[.]88[.]172[.]33: it POSTs JSON telemetry to hxxp://167[.]88[.]172[.]33:8087/api/log and hxxp://167[.]88[.]172[.]33:8087/api/notify (body includes a user key, host name, OS string and username), and uploads a generated sysinfo.txt file via multipart POST to hxxp://167[.]88[.]172[.]33:8085/upload. Requests are sent with axios and carry custom Userkey, T and Validation headers; beacons are staggered with setTimeout delays of up to 30 seconds. The package declares axios as a runtime dependency solely to carry this traffic and provides no logging functionality. Its metadata is copied from unrelated projects (the description is taken from a vulnerability-management policy document, the bugs URL points to jsonspack[.]com, and there is no repository field).
- analyzed by
- Leitwacht
- first seen
- Oct 7, 2026, 09:36 AM
- analyzed
- Oct 7, 2026, 09:37 AM
Related advisories
- css-reading-display-polyfill@1.0.0
- css-display-reading-polyfill@1.0.0
- streak-metrics-math@1.0.1
- streak-metrics-core@1.0.0
- shift-v4-sdk@1.0.5
- shift-sdk-v5@5.0.1
- ohcm-culture-formatting@5.0.0
- llm-traces-app@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.