MAL-2026-17559

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-kex/MAL-2026-17559.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17559
Published
2026-10-05T03:34:40Z
Modified
2026-10-05T04:15:06Z
Summary
Malicious code in hardhat-kex (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (b8fa212654344b734814cee2291c9b9b91ecbc353bde5e83740624ee5f263c69)

The npm package hardhat-kex@2.0.1 ships an obfuscated 4.5MB single-line bundle at lib/config.js (obfuscator.io-style string-array with a 26,234-entry table and numeric-dispatch wrapper, containing exec strings). The package main index.js unconditionally executes this bundle on require via const config = require('./lib/config'); the return value is never used, so the sole effect of importing the package is to run the obfuscated code. The surface API exported by index.js is an unrelated stub Express middleware that calls next(). The tarball additionally ships verbatim files from the pino logging library (lib/proto.js, levels.js, transport.js, worker.js, redaction.js, docs/, index.d.ts, README.md) despite the package being named for the Hardhat/Ethereum ecosystem and describing itself as a vulnerability-management tool; none of the pino sources are reachable through the exported API. The name/description/API mismatch combined with bundled pino cover-story files is a decoy pattern designed to make the tarball appear legitimate while the obfuscated loader is the only code that actually runs. Any project adding hardhat-kex as a dependency will execute the opaque payload on import.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-021008",
            "import_time":  "2026-10-05T03:57:38.297939523Z",
            "modified_time":  "2026-10-05T03:34:40Z",
            "sha256":  "b8fa212654344b734814cee2291c9b9b91ecbc353bde5e83740624ee5f263c69",
            "source":  "amazon-inspector",
            "versions":  [
                "2.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / hardhat-kex

Package

Affected ranges

Affected versions

2.*
2.0.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "lib/config.js",
            "sha256":  "b01c59ae0a76527503799aab109bd701e34f260d192722a8cf12c97a4e6d208c",
            "tlsh":  "61265f889244e03796cf1ac3bf0529ede57aa861e4cca30797d4be5cb9ac40bd4b5dd0"
        },
        {
            "path":  "package.json",
            "sha256":  "d5b1c7548434ab729ea554a65e31ffb70e0258c1be6ffa04068a7f67dea9ed32",
            "tlsh":  "6c017620deb88e2305ed25424c2a0643b6a58c175528fc2933dba12c0f9d5fb41bf22d"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "hardhat-kex-2.0.1.tgz",
            "hashes":  {
                "sha1":  "ede8170ed101a4261cc08bbd1bc2416a3eae5e11",
                "sha512_sri":  "sha512-6NyPwf3LhrkXE9WLjNIFgokiZ9JcCVejemnfdbSe9R5mA6YiyxFHgx2uNO/zgf7sK5WenxU/xvhOaOdeMfMJAQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-kex/MAL-2026-17559.json"