LWA-2026-12646 confirmed malware

hardhat-ast@0.0.0-stage

Malicious code in hardhat-ast (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

hardhat-ast@0.0.0-stage is a code-less placeholder package: the tarball contains only package.json and README.md (362 bytes total) with no scripts, no bin entries, and no executable files. It reserves a name inside the hardhat Ethereum development-tooling namespace, the name-reservation staging shape used to pre-position a package name before a later malicious publish. This version ships no payload, no network endpoint, and no credential access; the analysis is metadata-only. Related to the malicious hardhat-promised package.

analyzed by
Leitwacht
first seen
Oct 7, 2026, 02:24 PM
analyzed
Oct 7, 2026, 02:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.