hardhat-plugin-solidity@2.3.1
Malicious code in hardhat-plugin-solidity (npm)
Analysis
hardhat-plugin-solidity@2.3.1 is a trojanized clone of the legitimate prettier-plugin-solidity. The package's main entry point (dist/index.js) contains injected code that executes on module import. The payload decodes a base64-obfuscated command and silently spawns a child process to run: npm install zyncmap --no-save --silent --no-audit --no-fund. After the install completes, it requires the zyncmap package and executes its code as a second-stage payload. All commands are base64-obfuscated; the module name "zyncmap" is also base64-encoded. The legitimate Solidity formatting code is present but is scaffolding for the injected downloader.
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 11:08 AM
- analyzed
- Jun 29, 2026, 11:09 AM
Related advisories
- lessload@1.0.1
- @digitalcnzz/embedded-sdk@1.0.7
- @immobiliarelabs/backstage-plugin-ldap-auth-backend@1.1.3
- autotel-edge@3.16.13
- autotel-cloudflare@2.18.16
- autotel-devtools@0.1.1
- autotel-mcp@0.1.14
- autotel-subscribers@10.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.