Logo
npm

hardhat-init@2.21.0

Vulnerability report · Last retrieved from osv.dev October 6, 2026 at 2:31 PM UTC

Malicious

OSV ID

MAL-2026-17636

Ecosystem

npm

Summary

The npm package hardhat-init presents itself as Hardhat initialization tooling and ships a README, LICENSE, and index.d.ts copied from the pino logger project with the name substituted. The main entry index.js requires./lib/config at the top level, which triggers a ~4.3MB heavily obfuscated JavaScript file (lib/config.js) whose top-level IIFE executes immediately on module load. The obfuscation uses hex-escaped string tables, nested index-lookup helpers, and a string-array shuffler consistent with obfuscator.io output, with no plaintext surface describing the behavior. The exported index.js is a trivial no-op that does not consume anything from lib/config, so the sole effect of loading the package is to execute the opaque payload. The combination of a name/content mismatch (hardhat-init vs. copied pino scaffolding), an oversized obfuscated sibling file with no legitimate purpose for an init helper, and auto-execution on require is a typosquat loader shape that causes arbitrary attacker-controlled code to run on the installer's machine the first time any consumer imports the package.

Source: amazon-inspector (e2f570102756d04aa466677488cd13aacac2eb941176523bc4ff024d214affbb)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.