Logo
npm

hardhat-plus@2.21.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17508

Ecosystem

npm

Summary

hardhat-plus@2.21.0 is published under a name resembling the Ethereum development tool 'hardhat' but ships README, type definitions, and docs copied verbatim from the unrelated pino logger project (README.md references npmjs.com/package/pino; index.d.ts references github.com/pinojs/pino.git; package.json description is unrelated boilerplate). The package's main entry index.js requires./lib/config, which is a single ~4.5MB heavily obfuscated file using obfuscator.io transforms: hex-named identifiers, a self-mutating shuffled string-array (while(!![]){...f['push'](f['shift']())}), control-flow flattening, dispatched decode helpers, and pervasive \xNN escape literals. This opaque code runs unconditionally the moment the package is imported. There is no legitimate source, minification story, or documented purpose that accounts for a multi-megabyte obfuscated blob being loaded as a 'config' module in a package that presents itself as either a Hardhat plugin or a pino logger. The combination of name-based impersonation, mismatched cover-story documentation, and an obfuscated payload auto-executed on import is the standard delivery shape for supply-chain malware.

Source: amazon-inspector (02d908da8470ad86669b080d267b57174ccd77e5fd6ed2c371c430d98e869f2b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.