{"id":"MAL-2026-17560","summary":"Malicious code in hardhat-spack (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e59c971c63de9d0a7f66c26093f528164990af10eca00a3a36b97d0c8b0a6d0d)\nThe package is published as hardhat-spack but presents itself internally as a pino-like logger. Its main export is a middleware factory that spawns lib/caller.js as a detached child process. caller.js and lib/const.js define a fake process.env object whose DEV_API_KEY, DEV_SECRET_KEY, and DEV_SECRET_VALUE are base64 blobs; DEV_API_KEY decodes to https://iphub-encrypted.vercel.app/api/auth/f1f097d93c318c92f0c5. caller.js base64-decodes that URL, POSTs to it, and passes the response body to `new Function.constructor(\"require\", s)` and invokes it with the real require, giving the fetched JavaScript full Node capabilities (filesystem, child_process, network). The request is retried up to five times and failures are swallowed. The destination host is disposable Vercel infrastructure unrelated to any declared purpose, the URL and credential-shaped values are concealed with base64, and the executed code is attacker-mutable at any time.\n","modified":"2026-10-05T04:15:05.512601219Z","published":"2026-10-05T03:33:15Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020999","import_time":"2026-10-05T03:57:37.738361285Z","modified_time":"2026-10-05T03:33:15Z","sha256":"e59c971c63de9d0a7f66c26093f528164990af10eca00a3a36b97d0c8b0a6d0d","source":"amazon-inspector","versions":["3.0.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/hardhat-spack/v/3.0.2"}],"affected":[{"package":{"name":"hardhat-spack","ecosystem":"npm","purl":"pkg:npm/hardhat-spack"},"versions":["3.0.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"88d00cec2a6488c81d5080323a4ba81d789ec641345f2d177399cbc0527a74b8","tlsh":"f301bd4e22fd245c015112e6171fe0326010e4673d46d5d4378cd7425faa6bd2aa3bef","path":"lib/caller.js"}],"package_integrity":[{"filename":"hardhat-spack-3.0.2.tgz","hashes":{"sha512_sri":"sha512-gLNdS+RHbNFWUUxslSPxb5DjpjTYZFlr2XdU85v5qKE3I6Avjq3HI6Ig/GvyDiAhI4NI+YhQYEVtsap0Br7dDQ==","sha1":"5114952a0f6f925f77d7babfba8c0ac9348a4f2f"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-spack/MAL-2026-17560.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}