hardhat-pack@2.0.1
Malicious code in hardhat-pack (npm)
Analysis
hardhat-pack@2.0.1 is a combosquat name (the real package "hardhat" with a "-pack" suffix) that ships a trojanized copy of the pino logger: the bundled documentation, type definitions and lib/ tree are cloned from pino, while the entry point index.js is a no-op Express middleware stub that loads a 4.5 MB obfuscated payload at lib/config.js (javascript-obfuscator output with hex/unicode-escaped _0x identifiers). When the package is installed or required, the payload fingerprints the host and beacons it to a hardcoded remote endpoint: a multipart POST of a sysinfo.txt file (hostname, OS version, username, platform, timestamp) to hxxp://167[.]88[.]172[.]33:8085/upload, and JSON POSTs to hxxp://167[.]88[.]172[.]33:8087/api/notify ({"ukey":309,"t":3,"host":"309_<hostname>","os":...,"username":...}) and hxxp://167[.]88[.]172[.]33:8087/api/log ("Starting client"). Requests carry an axios user agent and a Validation HMAC header, and repeat on a timer. No credential, token or wallet access was observed; the payload's purpose is covert host reconnaissance and beaconing to attacker-controlled infrastructure.
- analyzed by
- Leitwacht
- first seen
- Oct 7, 2026, 03:16 PM
- analyzed
- Oct 7, 2026, 03:23 PM
Related advisories
- hardhat-bits@2.21.0
- hardhat-deep@2.0.1
- random-certs@0.0.1
- dotenv-runtime@1.0.0
- hardhat-promised@2.21.0
- solidity-map@2.21.0
- @subql/common@5.8.3
- hardhat-kex@2.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.