MAL-2026-17658

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-bits/MAL-2026-17658.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17658
Published
2026-10-08T03:39:07Z
Modified
2026-10-08T04:00:05Z
Summary
Malicious code in hardhat-bits (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (4e10f22980d33eea7649312f6b2b0a94637e5b4da400f7d585c58b6902a77944)

The package is published as hardhat-bits but its README, LICENSE, docs/, and lib/* files are copied verbatim from the pino logger project, providing cover for an inserted file at lib/config.js. index.js performs const config = require('./lib/config') at the top level, so the file executes unconditionally when the module is required. lib/config.js is a single-line, ~4.47 MB obfuscator.io output: a 26,130-entry shuffled string array with a rotating decoder, hex-escaped member access, RC4-style key-schedule string decoding, control-flow flattening, and a self-defending IIFE. The exported middleware in index.js is a no-op (_req, _res, next) => next(), so the obfuscated module serves no documented purpose in the public API. The combination of name/branding mismatch (hardhat tooling name, pino content), a stub public API, and a multi-megabyte obfuscated blob auto-executed on import matches the trojan-loader shape used by npm supply-chain malware; any installer that requires hardhat-bits runs attacker-controlled code hidden behind the obfuscation.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021121",
            "import_time": "2026-10-08T03:50:29.289732007Z",
            "modified_time": "2026-10-08T03:39:07Z",
            "sha256": "4e10f22980d33eea7649312f6b2b0a94637e5b4da400f7d585c58b6902a77944",
            "source": "amazon-inspector",
            "versions": [
                "2.21.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / hardhat-bits

Package

Affected ranges

Affected versions

2.*
2.21.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "index.js",
            "sha256": "4e6c4e61a7019ab0affe9c2d20e36701b330ec357be205930355bac1464f9316",
            "tlsh": "0421149124d560ce9938dac0f6306115acdbc677260752b3bdfc97c927860080161fba"
        },
        {
            "path": "lib/config.js",
            "sha256": "34cba8ace8486e69dbb70bcedc0f5e2a72b70735afb21071f4ba2a7b6c8f3153",
            "tlsh": "5e265fec9591c037d6dd1b53bf0929e8e17ea8aa95ccb587853cbda829bc00fc560cd4"
        },
        {
            "path": "package.json",
            "sha256": "2587db067c5c545cc5025470b1043f7ced5a1aa547dc57876076576e9fb40d09",
            "tlsh": "0d017620deb88e2301ed25425c2a4643b6618c175528fc2932dba12c0f9d5ff02ff21e"
        }
    ],
    "package_integrity": [
        {
            "filename": "hardhat-bits-2.21.0.tgz",
            "hashes": {
                "sha1": "12b0e1e77b1386de9d31e6415c29de95c8fff0e7",
                "sha512_sri": "sha512-owxGBrkFMQg0h3xXsv53Eg8UNKeO5q6aFQ/CPn9yZRIBL5ggLcHajRsYJMLI22DjSsP5Amh7C7xTMnNel+4l2Q=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-bits/MAL-2026-17658.json"