-= Per source details. Do not edit below this line.=-
The npm package hardhat-deep@2.0.1 is a trojanised shell. Its tarball copies the pino logger source tree (README, SECURITY.md, index.d.ts, lib/proto.js, lib/transport.js, lib/worker.js, lib/levels.js, lib/multistream.js, etc.) verbatim, while the package name and manifest description target the Hardhat ecosystem. The only novel file is lib/config.js, a single-line 4,499,968-byte obfuscator.io bundle with a 26,234-entry rotated string array, two decoder functions, hex-encoded strings and control-flow flattening. The package's top-level index.js is modified from pino's original to unconditionally require('./lib/config'), so any consumer that requires or imports hardhat-deep executes this opaque payload inside the installer's Node process. The exported middleware is a no-op cover with no logger functionality, so running the obfuscated blob is the only effect of installing or loading the package. The author identity (Robert King hello@jsonspack.com, jsonspack.com) is unrelated to either Hardhat or pinojs.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021132",
"import_time": "2026-10-08T03:50:30.012677686Z",
"modified_time": "2026-10-08T03:43:45Z",
"sha256": "fde0a4a0ec197ee1aab9acf20ea157268b553fdb5669c545c27d92cbf89fe304",
"source": "amazon-inspector",
"versions": [
"2.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "4e6c4e61a7019ab0affe9c2d20e36701b330ec357be205930355bac1464f9316",
"tlsh": "0421149124d560ce9938dac0f6306115acdbc677260752b3bdfc97c927860080161fba"
},
{
"path": "lib/config.js",
"sha256": "b01c59ae0a76527503799aab109bd701e34f260d192722a8cf12c97a4e6d208c",
"tlsh": "61265f889244e03796cf1ac3bf0529ede57aa861e4cca30797d4be5cb9ac40bd4b5dd0"
},
{
"path": "package.json",
"sha256": "01edd4a40b2c3451b1f0d54d673371e6f02d372239ffa53b6741dd3ab5d80f7f",
"tlsh": "68017620deb88e2301ed25424c2a0603b6a58c179528fc2933dba12c0f9d5fb41bf22d"
}
],
"package_integrity": [
{
"filename": "hardhat-deep-2.0.1.tgz",
"hashes": {
"sha1": "3bb404b0ad72c15aa11b1e5d1a3998e73007ae08",
"sha512_sri": "sha512-2JPj1GPPn4tLe4QssJhj6F5T8hHqAEpCqvgoHkZEnMUV/pr1bL+ap3aW+wT5HsZNqJ7SjlG4FrZn3HZZpBWS4A=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-deep/MAL-2026-17659.json"