hardhat-test-log@1.1.0
Malicious code in hardhat-test-log (npm)
Analysis
When loaded as a Mocha reporter, this package spawns a hidden detached Node.js child process (lib/syncResolve.js) that fetches a second-stage payload from `hxxps://www[.]jsonkeeper[.]com/b/NB36A` and executes it via the Function constructor with full access to the Node.js require system. The package is a trojanized clone of the legitimate eth-gas-reporter: its main entry point contains a dead-code guard (`var opt = 1`) that bypasses the real reporter logic and triggers the downloader instead. The attacker-controlled JSONkeeper URL delivers arbitrary remote code. IOCs: C2 URL `hxxps://www[.]jsonkeeper[.]com/b/NB36A`, HTTP header `x-secret-key: _`, max 5 retries on failure.
- analyzed by
- Leitwacht
- first seen
- Jun 24, 2026, 12:00 AM
- analyzed
- Jun 24, 2026, 12:01 AM
Related advisories
- theme-color-picker@2.0.28
- chai-as-operated@6.0.3
- airbnb-airlock@99.0.0
- set-cookie-ease@1.1.5
- analysis-chart@2.0.8
- web3-token-helper@1.1.3
- zod-pino@1.0.122
- node-core-libs@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.