hardhat-option@2.0.1
Malicious code in hardhat-option (npm)
Analysis
hardhat-option@2.0.1 ships a trojanized copy of the pino logging library (index.js, lib/, docs/ are pino source) with an injected payload in lib/config.js — a 4.5 MB single-line javascript-obfuscator blob using hex-escaped identifiers and an encoded string array. Requiring the package executes the obfuscated payload, which performs host reconnaissance (hostname, OS, username, platform) and beacons over HTTP to a hardcoded command-and-control server at 167[.]88[.]172[.]33: it POSTs a multipart/form-data upload of sysinfo.txt to hxxp://167[.]88[.]172[.]33:8085/upload, and posts JSON telemetry to hxxp://167[.]88[.]172[.]33:8087/api/log and hxxp://167[.]88[.]172[.]33:8087/api/notify containing a numeric user key (ukey 309), host, OS and username, with a "Validation" HMAC header, via axios. The requests repeat on a timer (33 scheduled delays of up to 30 seconds). The package declares no source repository and its description is unrelated to its code.
- analyzed by
- Leitwacht
- first seen
- Oct 7, 2026, 09:37 AM
- analyzed
- Oct 7, 2026, 09:38 AM
Related advisories
- hardhat-deep@2.0.1
- random-certs@0.0.1
- dotenv-runtime@1.0.0
- hardhat-promised@2.21.0
- solidity-map@2.21.0
- @subql/common@5.8.3
- hardhat-kex@2.0.1
- hardhat-spack@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.