Logo
npm

hardhat-bits@2.21.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC

Malicious

OSV ID

MAL-2026-17658

Ecosystem

npm

Summary

The package is published as hardhat-bits but its README, LICENSE, docs/, and lib/* files are copied verbatim from the pino logger project, providing cover for an inserted file at lib/config.js. index.js performs const config = require('./lib/config') at the top level, so the file executes unconditionally when the module is required. lib/config.js is a single-line, ~4.47 MB obfuscator.io output: a 26,130-entry shuffled string array with a rotating decoder, hex-escaped member access, RC4-style key-schedule string decoding, control-flow flattening, and a self-defending IIFE. The exported middleware in index.js is a no-op (_req, _res, next) => next(), so the obfuscated module serves no documented purpose in the public API. The combination of name/branding mismatch (hardhat tooling name, pino content), a stub public API, and a multi-megabyte obfuscated blob auto-executed on import matches the trojan-loader shape used by npm supply-chain malware; any installer that requires hardhat-bits runs attacker-controlled code hidden behind the obfuscation.

Source: amazon-inspector (4e10f22980d33eea7649312f6b2b0a94637e5b4da400f7d585c58b6902a77944)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.