-= Per source details. Do not edit below this line.=-
The package is published as hardhat-bits but its README, LICENSE, docs/, and lib/* files are copied verbatim from the pino logger project, providing cover for an inserted file at lib/config.js. index.js performs const config = require('./lib/config') at the top level, so the file executes unconditionally when the module is required. lib/config.js is a single-line, ~4.47 MB obfuscator.io output: a 26,130-entry shuffled string array with a rotating decoder, hex-escaped member access, RC4-style key-schedule string decoding, control-flow flattening, and a self-defending IIFE. The exported middleware in index.js is a no-op (_req, _res, next) => next(), so the obfuscated module serves no documented purpose in the public API. The combination of name/branding mismatch (hardhat tooling name, pino content), a stub public API, and a multi-megabyte obfuscated blob auto-executed on import matches the trojan-loader shape used by npm supply-chain malware; any installer that requires hardhat-bits runs attacker-controlled code hidden behind the obfuscation.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021121",
"import_time": "2026-10-08T03:50:29.289732007Z",
"modified_time": "2026-10-08T03:39:07Z",
"sha256": "4e10f22980d33eea7649312f6b2b0a94637e5b4da400f7d585c58b6902a77944",
"source": "amazon-inspector",
"versions": [
"2.21.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "4e6c4e61a7019ab0affe9c2d20e36701b330ec357be205930355bac1464f9316",
"tlsh": "0421149124d560ce9938dac0f6306115acdbc677260752b3bdfc97c927860080161fba"
},
{
"path": "lib/config.js",
"sha256": "34cba8ace8486e69dbb70bcedc0f5e2a72b70735afb21071f4ba2a7b6c8f3153",
"tlsh": "5e265fec9591c037d6dd1b53bf0929e8e17ea8aa95ccb587853cbda829bc00fc560cd4"
},
{
"path": "package.json",
"sha256": "2587db067c5c545cc5025470b1043f7ced5a1aa547dc57876076576e9fb40d09",
"tlsh": "0d017620deb88e2301ed25425c2a4643b6618c175528fc2932dba12c0f9d5ff02ff21e"
}
],
"package_integrity": [
{
"filename": "hardhat-bits-2.21.0.tgz",
"hashes": {
"sha1": "12b0e1e77b1386de9d31e6415c29de95c8fff0e7",
"sha512_sri": "sha512-owxGBrkFMQg0h3xXsv53Eg8UNKeO5q6aFQ/CPn9yZRIBL5ggLcHajRsYJMLI22DjSsP5Amh7C7xTMnNel+4l2Q=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-bits/MAL-2026-17658.json"