Logo
npm

hardhat-spack@3.0.2

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17560

Ecosystem

npm

Summary

The package is published as hardhat-spack but presents itself internally as a pino-like logger. Its main export is a middleware factory that spawns lib/caller.js as a detached child process. caller.js and lib/const.js define a fake process.env object whose DEV_API_KEY, DEV_SECRET_KEY, and DEV_SECRET_VALUE are base64 blobs; DEV_API_KEY decodes to https://iphub-encrypted.vercel.app/api/auth/f1f097d93c318c92f0c5. caller.js base64-decodes that URL, POSTs to it, and passes the response body to new Function.constructor("require", s) and invokes it with the real require, giving the fetched JavaScript full Node capabilities (filesystem, child_process, network). The request is retried up to five times and failures are swallowed. The destination host is disposable Vercel infrastructure unrelated to any declared purpose, the URL and credential-shaped values are concealed with base64, and the executed code is attacker-mutable at any time.

Source: amazon-inspector (e59c971c63de9d0a7f66c26093f528164990af10eca00a3a36b97d0c8b0a6d0d)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.