hardhat-kex@2.0.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17559
Ecosystem
npm
Summary
The npm package hardhat-kex@2.0.1 ships an obfuscated 4.5MB single-line bundle at lib/config.js (obfuscator.io-style string-array with a 26,234-entry table and numeric-dispatch wrapper, containing exec strings). The package main index.js unconditionally executes this bundle on require via const config = require('./lib/config'); the return value is never used, so the sole effect of importing the package is to run the obfuscated code. The surface API exported by index.js is an unrelated stub Express middleware that calls next(). The tarball additionally ships verbatim files from the pino logging library (lib/proto.js, levels.js, transport.js, worker.js, redaction.js, docs/, index.d.ts, README.md) despite the package being named for the Hardhat/Ethereum ecosystem and describing itself as a vulnerability-management tool; none of the pino sources are reachable through the exported API. The name/description/API mismatch combined with bundled pino cover-story files is a decoy pattern designed to make the tarball appear legitimate while the obfuscated loader is the only code that actually runs. Any project adding hardhat-kex as a dependency will execute the opaque payload on import.
Source: amazon-inspector (b8fa212654344b734814cee2291c9b9b91ecbc353bde5e83740624ee5f263c69)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.