LWA-2026-12647 confirmed malware

hardhat-bits@2.21.0

Malicious code in hardhat-bits (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1140 · Deobfuscate/Decode Files or Information

Analysis

hardhat-bits@2.21.0 is a trojanized clone of the pino logging library. It ships pino's README, docs/, index.d.ts and lib/ modules verbatim (lib/meta.js reports pino version 9.6.0) under a combosquat name, but replaces the real lib/config.js with a 4.47 MB obfuscated payload. The entry point index.js requires ./lib/config at load time, so the obfuscated code runs as soon as the module is imported — no install hook is needed. The payload uses a large encoded string array with an RC4/base64 decoder, hex-escaped property names, and self-defending regex checks that detect a debugger or reformatted source and abort. Its string table is encoded, so the payload's endpoints are not present as plaintext in the shipped file; the entry point imports child_process.spawn and the package declares axios as a dependency, providing the process-execution and HTTP primitives for the hidden stage. Package metadata is fabricated: author "Robert King" <[account]>, bugs URL hxxps://jsonspack[.]com/issues, and npm scripts smoke:pino / smoke:file that run node ./index.js and node ./file.js.

analyzed by
Leitwacht
first seen
Oct 7, 2026, 02:37 PM
analyzed
Oct 7, 2026, 02:38 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.