LWA-2026-12644 confirmed malware

hardhat-option@2.0.1

Malicious code in hardhat-option (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

hardhat-option@2.0.1 ships a trojanized copy of the pino logging library (index.js, lib/, docs/ are pino source) with an injected payload in lib/config.js — a 4.5 MB single-line javascript-obfuscator blob using hex-escaped identifiers and an encoded string array. Requiring the package executes the obfuscated payload, which performs host reconnaissance (hostname, OS, username, platform) and beacons over HTTP to a hardcoded command-and-control server at 167[.]88[.]172[.]33: it POSTs a multipart/form-data upload of sysinfo.txt to hxxp://167[.]88[.]172[.]33:8085/upload, and posts JSON telemetry to hxxp://167[.]88[.]172[.]33:8087/api/log and hxxp://167[.]88[.]172[.]33:8087/api/notify containing a numeric user key (ukey 309), host, OS and username, with a "Validation" HMAC header, via axios. The requests repeat on a timer (33 scheduled delays of up to 30 seconds). The package declares no source repository and its description is unrelated to its code.

analyzed by
Leitwacht
first seen
Oct 7, 2026, 09:37 AM
analyzed
Oct 7, 2026, 09:38 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.