Logo
npm

hardhat-pack@2.0.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC

Malicious

OSV ID

MAL-2026-17661

Ecosystem

npm

Summary

The package is published as hardhat-pack, a name shape that resembles the Hardhat Ethereum tooling ecosystem, but its README, LICENSE, TypeScript declarations and library source are copied verbatim from the unrelated pino logger. The only material divergence from upstream pino is that index.js adds const config = require('./lib/config'); at the top level, and lib/config.js is a single-line 4.4MB obfuscator.io payload: an IIFE with a ~26,000-entry hex-escaped string array and a rotating decoder. Nothing in the shipped source references config for a legitimate purpose, and the package carries no native build, no vendored SDK, and no other justification for a multi-megabyte opaque blob. The package also declares axios as a runtime dependency, consistent with network exfiltration or remote fetch from inside the decoded payload. Any process that imports hardhat-pack hands the opaque payload to the JavaScript engine on first require.

Source: amazon-inspector (b39859996d5d333a776d3ed42a203450ea588adefd91ba46a25a0bef0b17cf02)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.