MAL-2026-17659

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-deep/MAL-2026-17659.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17659
Published
2026-10-08T03:43:45Z
Modified
2026-10-08T04:00:05Z
Summary
Malicious code in hardhat-deep (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (fde0a4a0ec197ee1aab9acf20ea157268b553fdb5669c545c27d92cbf89fe304)

The npm package hardhat-deep@2.0.1 is a trojanised shell. Its tarball copies the pino logger source tree (README, SECURITY.md, index.d.ts, lib/proto.js, lib/transport.js, lib/worker.js, lib/levels.js, lib/multistream.js, etc.) verbatim, while the package name and manifest description target the Hardhat ecosystem. The only novel file is lib/config.js, a single-line 4,499,968-byte obfuscator.io bundle with a 26,234-entry rotated string array, two decoder functions, hex-encoded strings and control-flow flattening. The package's top-level index.js is modified from pino's original to unconditionally require('./lib/config'), so any consumer that requires or imports hardhat-deep executes this opaque payload inside the installer's Node process. The exported middleware is a no-op cover with no logger functionality, so running the obfuscated blob is the only effect of installing or loading the package. The author identity (Robert King hello@jsonspack.com, jsonspack.com) is unrelated to either Hardhat or pinojs.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021132",
            "import_time": "2026-10-08T03:50:30.012677686Z",
            "modified_time": "2026-10-08T03:43:45Z",
            "sha256": "fde0a4a0ec197ee1aab9acf20ea157268b553fdb5669c545c27d92cbf89fe304",
            "source": "amazon-inspector",
            "versions": [
                "2.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / hardhat-deep

Package

Affected ranges

Affected versions

2.*
2.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "index.js",
            "sha256": "4e6c4e61a7019ab0affe9c2d20e36701b330ec357be205930355bac1464f9316",
            "tlsh": "0421149124d560ce9938dac0f6306115acdbc677260752b3bdfc97c927860080161fba"
        },
        {
            "path": "lib/config.js",
            "sha256": "b01c59ae0a76527503799aab109bd701e34f260d192722a8cf12c97a4e6d208c",
            "tlsh": "61265f889244e03796cf1ac3bf0529ede57aa861e4cca30797d4be5cb9ac40bd4b5dd0"
        },
        {
            "path": "package.json",
            "sha256": "01edd4a40b2c3451b1f0d54d673371e6f02d372239ffa53b6741dd3ab5d80f7f",
            "tlsh": "68017620deb88e2301ed25424c2a0603b6a58c179528fc2933dba12c0f9d5fb41bf22d"
        }
    ],
    "package_integrity": [
        {
            "filename": "hardhat-deep-2.0.1.tgz",
            "hashes": {
                "sha1": "3bb404b0ad72c15aa11b1e5d1a3998e73007ae08",
                "sha512_sri": "sha512-2JPj1GPPn4tLe4QssJhj6F5T8hHqAEpCqvgoHkZEnMUV/pr1bL+ap3aW+wT5HsZNqJ7SjlG4FrZn3HZZpBWS4A=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-deep/MAL-2026-17659.json"