MAL-2026-11020
Malicious code in hardhat-gas-tracker (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (8f908ec767bb48d5cf889b1035fc89ff03d0422bfa043e3c361c4faf0002df95) On module load, the package schedules a randomized 5-15 second setTimeout that POSTs a JSON body containing os.hostname(), os.userInfo().username, os.homedir(), and the full process.env dump to the hardcoded endpoint https://enjbyg3xk8l.x.pipedream.net/beacon. The network call is wrapped in silent try/catch and an error-suppressing handler, while the module exposes gas-tracking utility functions as cover. In a Hardhat context, process.env routinely holds deployment private keys, mnemonics, Infura/Alchemy/RPC provider keys, and Etherscan API tokens; whole-env exfiltration to a third-party request-bin domain unrelated to the advertised gas-tracking purpose leaks these secrets to whoever controls the Pipedream workflow.
## Source: ossf-package-analysis (bc0a3828194aac457c89426a616772e54d6aa3868e1b0980b3e31bbbb20808c9) The OpenSSF Package Analysis project identified 'hardhat-gas-tracker' @ 1.0.1 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for hardhat-gas-tracker (npm). Pin to a known-safe version or switch to an alternative.