LWA-2026-12648 confirmed malware

hardhat-pack@2.0.1

Malicious code in hardhat-pack (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

hardhat-pack@2.0.1 is a combosquat name (the real package "hardhat" with a "-pack" suffix) that ships a trojanized copy of the pino logger: the bundled documentation, type definitions and lib/ tree are cloned from pino, while the entry point index.js is a no-op Express middleware stub that loads a 4.5 MB obfuscated payload at lib/config.js (javascript-obfuscator output with hex/unicode-escaped _0x identifiers). When the package is installed or required, the payload fingerprints the host and beacons it to a hardcoded remote endpoint: a multipart POST of a sysinfo.txt file (hostname, OS version, username, platform, timestamp) to hxxp://167[.]88[.]172[.]33:8085/upload, and JSON POSTs to hxxp://167[.]88[.]172[.]33:8087/api/notify ({"ukey":309,"t":3,"host":"309_<hostname>","os":...,"username":...}) and hxxp://167[.]88[.]172[.]33:8087/api/log ("Starting client"). Requests carry an axios user agent and a Validation HMAC header, and repeat on a timer. No credential, token or wallet access was observed; the payload's purpose is covert host reconnaissance and beaconing to attacker-controlled infrastructure.

analyzed by
Leitwacht
first seen
Oct 7, 2026, 03:16 PM
analyzed
Oct 7, 2026, 03:23 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.