hardhat-bits@2.21.0
Malicious code in hardhat-bits (npm)
Analysis
hardhat-bits@2.21.0 is a trojanized clone of the pino logging library. It ships pino's README, docs/, index.d.ts and lib/ modules verbatim (lib/meta.js reports pino version 9.6.0) under a combosquat name, but replaces the real lib/config.js with a 4.47 MB obfuscated payload. The entry point index.js requires ./lib/config at load time, so the obfuscated code runs as soon as the module is imported — no install hook is needed. The payload uses a large encoded string array with an RC4/base64 decoder, hex-escaped property names, and self-defending regex checks that detect a debugger or reformatted source and abort. Its string table is encoded, so the payload's endpoints are not present as plaintext in the shipped file; the entry point imports child_process.spawn and the package declares axios as a dependency, providing the process-execution and HTTP primitives for the hidden stage. Package metadata is fabricated: author "Robert King" <[account]>, bugs URL hxxps://jsonspack[.]com/issues, and npm scripts smoke:pino / smoke:file that run node ./index.js and node ./file.js.
- analyzed by
- Leitwacht
- first seen
- Oct 7, 2026, 02:37 PM
- analyzed
- Oct 7, 2026, 02:38 PM
Related advisories
- random-certs@0.0.1
- dotenv-runtime@1.0.0
- @subql/common@5.8.3
- hardhat-spack@3.0.2
- tailwind-contact-forms@0.5.9
- testmgkregme@1.0.1
- punypump@1.2.4
- discord-mfa@3.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.