MAL-2026-17233
Malicious code in hardhat-lock (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (035a099bd6a60e41f1e1cbc1b70f27fecb9bef3f12d54e016d6991b581fc880f) The npm package hardhat-lock@2.21.0 publishes itself as a logger/middleware but its identity and contents are inconsistent with that purpose: README badges, LICENSE, index.d.ts and docs/* are copied from the unrelated pino project (maintained by pinojs), while the package name squats the Ethereum-tooling keyword 'hardhat'. index.js unconditionally executes require('./lib/config') at module load, and lib/config.js is a ~4MB obfuscator.io-style single-line file (rotated string array of 23,981 entries, hex-escaped tokens, numeric wrapper decoders mt/mw/M0..M5/K/R/s/G, control-flow flattening, and 40,131 inline decoder replacements confirmed by webcrack) whose top-level IIFE runs the moment any downstream code does require('hardhat-lock'). The combination — impersonation of an established package under a different scope-adjacent name, opaque multi-megabyte obfuscated blob with no plausible logging use, and guaranteed import-time execution — is a supply-chain payload carrier: installing and loading the package places attacker-controlled code inside the consumer's Node.js process with unrestricted access to environment variables, filesystem, and network.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for hardhat-lock (npm). Pin to a known-safe version or switch to an alternative.