LWA-2026-5948 MAL-2026-6369 ↗ confirmed malware

hardhat-test-log@1.1.0

Malicious code in hardhat-test-log (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

When loaded as a Mocha reporter, this package spawns a hidden detached Node.js child process (lib/syncResolve.js) that fetches a second-stage payload from `hxxps://www[.]jsonkeeper[.]com/b/NB36A` and executes it via the Function constructor with full access to the Node.js require system. The package is a trojanized clone of the legitimate eth-gas-reporter: its main entry point contains a dead-code guard (`var opt = 1`) that bypasses the real reporter logic and triggers the downloader instead. The attacker-controlled JSONkeeper URL delivers arbitrary remote code. IOCs: C2 URL `hxxps://www[.]jsonkeeper[.]com/b/NB36A`, HTTP header `x-secret-key: _`, max 5 retries on failure.

analyzed by
Leitwacht
first seen
Jun 24, 2026, 12:00 AM
analyzed
Jun 24, 2026, 12:01 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.