-= Per source details. Do not edit below this line.=-
hardhat-plus@2.21.0 is published under a name resembling the Ethereum development tool 'hardhat' but ships README, type definitions, and docs copied verbatim from the unrelated pino logger project (README.md references npmjs.com/package/pino; index.d.ts references github.com/pinojs/pino.git; package.json description is unrelated boilerplate). The package's main entry index.js requires./lib/config, which is a single ~4.5MB heavily obfuscated file using obfuscator.io transforms: hex-named identifiers, a self-mutating shuffled string-array (while(!![]){...f'push'}), control-flow flattening, dispatched decode helpers, and pervasive \xNN escape literals. This opaque code runs unconditionally the moment the package is imported. There is no legitimate source, minification story, or documented purpose that accounts for a multi-megabyte obfuscated blob being loaded as a 'config' module in a package that presents itself as either a Hardhat plugin or a pino logger. The combination of name-based impersonation, mismatched cover-story documentation, and an obfuscated payload auto-executed on import is the standard delivery shape for supply-chain malware.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020973",
"import_time": "2026-10-04T23:40:47.353640666Z",
"modified_time": "2026-10-04T23:28:23Z",
"sha256": "02d908da8470ad86669b080d267b57174ccd77e5fd6ed2c371c430d98e869f2b",
"source": "amazon-inspector",
"versions": [
"2.21.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "lib/config.js",
"sha256": "859f8450de820d002dc9b34c2691b1c8272d015aa423bdba17c87654a558b535",
"tlsh": "662662d8754dd0239ade1a63bf4a7ed8933b5da7c4c8a51bc5687e9c68bc807c0a1cd0"
},
{
"path": "package.json",
"sha256": "13f4ed481c16fe127f06b57fdc170c812c72e51bc563ecfaba9a644eb47c42fc",
"tlsh": "af017620deb88e2301ed25424c2a0643b6a18c179528fd2932dba12c4fad5fb01ff21e"
}
],
"package_integrity": [
{
"filename": "hardhat-plus-2.21.0.tgz",
"hashes": {
"sha1": "c23e0657d54c4bda45e3f8c0fa95a9a0470faacb",
"sha512_sri": "sha512-1f1Qb2ROS42tFxWyrONa/zPmIt8+2e6DpRkU67xyhHBhY1ikObPKMosgvPR2SgGu+iP0FR5leGBVmH20n1sYaA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-plus/MAL-2026-17508.json"