LWA-2026-12646 confirmed malware
hardhat-ast@0.0.0-stage
Malicious code in hardhat-ast (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
hardhat-ast@0.0.0-stage is a code-less placeholder package: the tarball contains only package.json and README.md (362 bytes total) with no scripts, no bin entries, and no executable files. It reserves a name inside the hardhat Ethereum development-tooling namespace, the name-reservation staging shape used to pre-position a package name before a later malicious publish. This version ships no payload, no network endpoint, and no credential access; the analysis is metadata-only. Related to the malicious hardhat-promised package.
- analyzed by
- Leitwacht
- first seen
- Oct 7, 2026, 02:24 PM
- analyzed
- Oct 7, 2026, 02:24 PM
Related advisories
- hardhat-option@2.0.1
- hardhat-deep@2.0.1
- wix-ssr-thunderbolt-grid-polyfill@0.1.0
- css-reading-display-polyfill@1.0.0
- dotenv-runtime@1.0.0
- hardhat-promised@2.21.0
- css-jptvix-polyfill@1.0.0
- solidity-map@2.21.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.