hardhat-jsx@2.0.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17507
Ecosystem
npm
Summary
The package is published as 'hardhat-jsx' but its metadata, documentation, and lib/ layout impersonate the pino logger (keywords 'fast','logger','stream','json'; shipped docs reference pinojs/pino). The main entry index.js unconditionally requires./lib/config, which is a 4,499,968-byte single-line obfuscator.io artifact — a hex-escaped string array of ~26,234 entries with string-array rotation and control-flow flattening (22,707 decoder-wrapper inlines, 44,499 string-inline changes). A legitimate pino 'config' module is ~1-2KB; a multi-megabyte obfuscated blob auto-loaded by the main entry is a loader/dropper. The surface index.js exports a no-op Express-style middleware whose comment claims it 'triggers a background process', providing a cover story adjacent to the obfuscated require. Loading the package via require/import executes the opaque payload in the installer's process. The name/content mismatch (hardhat-jsx vs. pino impersonation), the stub façade, and the heavily obfuscated auto-loaded module together form a trojan-package shape.
Source: amazon-inspector (62ac44be2745338b73861690e7f979216fdfc6c3797dfa2f450e9063aa4158d1)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.