Logo
npm

hardhat-lock@2.21.0

Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 11:09 PM UTC

Malicious

OSV ID

MAL-2026-17233

Ecosystem

npm

Summary

The npm package hardhat-lock@2.21.0 publishes itself as a logger/middleware but its identity and contents are inconsistent with that purpose: README badges, LICENSE, index.d.ts and docs/* are copied from the unrelated pino project (maintained by pinojs), while the package name squats the Ethereum-tooling keyword 'hardhat'. index.js unconditionally executes require('./lib/config') at module load, and lib/config.js is a ~4MB obfuscator.io-style single-line file (rotated string array of 23,981 entries, hex-escaped tokens, numeric wrapper decoders mt/mw/M0..M5/K/R/s/G, control-flow flattening, and 40,131 inline decoder replacements confirmed by webcrack) whose top-level IIFE runs the moment any downstream code does require('hardhat-lock'). The combination — impersonation of an established package under a different scope-adjacent name, opaque multi-megabyte obfuscated blob with no plausible logging use, and guaranteed import-time execution — is a supply-chain payload carrier: installing and loading the package places attacker-controlled code inside the consumer's Node.js process with unrestricted access to environment variables, filesystem, and network.

Source: amazon-inspector (035a099bd6a60e41f1e1cbc1b70f27fecb9bef3f12d54e016d6991b581fc880f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.