MAL-2026-17560

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-spack/MAL-2026-17560.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17560
Published
2026-10-05T03:33:15Z
Modified
2026-10-05T04:15:05Z
Summary
Malicious code in hardhat-spack (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e59c971c63de9d0a7f66c26093f528164990af10eca00a3a36b97d0c8b0a6d0d)

The package is published as hardhat-spack but presents itself internally as a pino-like logger. Its main export is a middleware factory that spawns lib/caller.js as a detached child process. caller.js and lib/const.js define a fake process.env object whose DEV_API_KEY, DEV_SECRET_KEY, and DEV_SECRET_VALUE are base64 blobs; DEV_API_KEY decodes to https://iphub-encrypted.vercel.app/api/auth/f1f097d93c318c92f0c5. caller.js base64-decodes that URL, POSTs to it, and passes the response body to new Function.constructor("require", s) and invokes it with the real require, giving the fetched JavaScript full Node capabilities (filesystem, child_process, network). The request is retried up to five times and failures are swallowed. The destination host is disposable Vercel infrastructure unrelated to any declared purpose, the URL and credential-shaped values are concealed with base64, and the executed code is attacker-mutable at any time.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020999",
            "import_time":  "2026-10-05T03:57:37.738361285Z",
            "modified_time":  "2026-10-05T03:33:15Z",
            "sha256":  "e59c971c63de9d0a7f66c26093f528164990af10eca00a3a36b97d0c8b0a6d0d",
            "source":  "amazon-inspector",
            "versions":  [
                "3.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / hardhat-spack

Package

Name
hardhat-spack
View open source insights on deps.dev
Purl
pkg:npm/hardhat-spack

Affected ranges

Affected versions

3.*
3.0.2

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "lib/caller.js",
            "sha256":  "88d00cec2a6488c81d5080323a4ba81d789ec641345f2d177399cbc0527a74b8",
            "tlsh":  "f301bd4e22fd245c015112e6171fe0326010e4673d46d5d4378cd7425faa6bd2aa3bef"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "hardhat-spack-3.0.2.tgz",
            "hashes":  {
                "sha1":  "5114952a0f6f925f77d7babfba8c0ac9348a4f2f",
                "sha512_sri":  "sha512-gLNdS+RHbNFWUUxslSPxb5DjpjTYZFlr2XdU85v5qKE3I6Avjq3HI6Ig/GvyDiAhI4NI+YhQYEVtsap0Br7dDQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-spack/MAL-2026-17560.json"