hardhat-hold@2.21.0
Malicious code in hardhat-hold (npm)
Analysis
hardhat-hold@2.21.0 is a combosquat package (named to resemble the hardhat Ethereum development tool) that functions as a C2 reconnaissance implant. On require(), the heavily-obfuscated payload in lib/config.js (4MB, javascript-obfuscator output) beacons system information to a remote server at 167[.]88[.]167[.]54:8087 and 167[.]88[.]167[.]54:8085. It POSTs JSON to /api/log and /api/notify containing the hostname, operating system, and username. It also POSTs a multipart file upload to /upload containing a sysinfo.txt file with hostname, OS, username, platform, and timestamp. The package performs sandbox detection via DNS queries before activating its C2 channel.
- analyzed by
- Leitwacht
- first seen
- Jul 31, 2026, 09:43 AM
- analyzed
- Jul 31, 2026, 09:43 AM
- weekly installs
- 191
Related advisories
- @latlongid/location@1.0.1
- streak-metrics-math@1.0.1
- streak-math-metrics@1.0.0
- streak-metrics-core@1.0.0
- supersig@1.0.5
- switchpaymentsapiserv-paypal@2.3.4
- add-two-numbers-x7q9m@1.0.0
- streak-view-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.