LWA-2026-7299 confirmed malware

hardhat-hold@2.21.0

Malicious code in hardhat-hold (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

hardhat-hold@2.21.0 is a combosquat package (named to resemble the hardhat Ethereum development tool) that functions as a C2 reconnaissance implant. On require(), the heavily-obfuscated payload in lib/config.js (4MB, javascript-obfuscator output) beacons system information to a remote server at 167[.]88[.]167[.]54:8087 and 167[.]88[.]167[.]54:8085. It POSTs JSON to /api/log and /api/notify containing the hostname, operating system, and username. It also POSTs a multipart file upload to /upload containing a sysinfo.txt file with hostname, OS, username, platform, and timestamp. The package performs sandbox detection via DNS queries before activating its C2 channel.

analyzed by
Leitwacht
first seen
Jul 31, 2026, 09:43 AM
analyzed
Jul 31, 2026, 09:43 AM
weekly installs
191

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.