hardhat-compile-ethers@0.0.1
Malicious code in hardhat-compile-ethers (npm)
Analysis
hardhat-compile-ethers is a trojanized clone impersonating the legitimate Hardhat plugin ecosystem for Ethereum development. When imported via require() in a hardhat.config file, the compiled entry point dist/src/index.js executes injected code that silently installs the zyncmap package from npm (npm install zyncmap --no-save --silent --no-audit --no-fund) via a spawned child process, then requires and executes the installed zyncmap module as a second-stage payload. The TypeScript source files are clean — the malicious code was injected only into the compiled JavaScript output, which is the code that runs at runtime.
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 03:00 PM
- analyzed
- Jun 29, 2026, 03:01 PM
Related advisories
- hardhat-plugin-solidity@2.3.1
- date-uuid@1.0.1
- @yhong91/vibetime@0.1.3
- weavedb-sdk@0.45.3
- friendly-greeter-demo@1.0.10
- free-anthropic-claude@5.3.0
- ts-ankle@1.1.0
- gptmini@4.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.