{"id":"MAL-2026-17659","summary":"Malicious code in hardhat-deep (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fde0a4a0ec197ee1aab9acf20ea157268b553fdb5669c545c27d92cbf89fe304)\nThe npm package hardhat-deep@2.0.1 is a trojanised shell. Its tarball copies the pino logger source tree (README, SECURITY.md, index.d.ts, lib/proto.js, lib/transport.js, lib/worker.js, lib/levels.js, lib/multistream.js, etc.) verbatim, while the package name and manifest description target the Hardhat ecosystem. The only novel file is lib/config.js, a single-line 4,499,968-byte obfuscator.io bundle with a 26,234-entry rotated string array, two decoder functions, hex-encoded strings and control-flow flattening. The package's top-level index.js is modified from pino's original to unconditionally `require('./lib/config')`, so any consumer that `require`s or `import`s hardhat-deep executes this opaque payload inside the installer's Node process. The exported middleware is a no-op cover with no logger functionality, so running the obfuscated blob is the only effect of installing or loading the package. The author identity (Robert King \u003chello@jsonspack.com\u003e, jsonspack.com) is unrelated to either Hardhat or pinojs.\n","modified":"2026-10-08T04:00:05.143158358Z","published":"2026-10-08T03:43:45Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-08T03:50:30.012677686Z","modified_time":"2026-10-08T03:43:45Z","sha256":"fde0a4a0ec197ee1aab9acf20ea157268b553fdb5669c545c27d92cbf89fe304","source":"amazon-inspector","versions":["2.0.1"],"id":"IN-MAL-2026-021132"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/hardhat-deep/v/2.0.1"}],"affected":[{"package":{"name":"hardhat-deep","ecosystem":"npm","purl":"pkg:npm/hardhat-deep"},"versions":["2.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-deep/MAL-2026-17659.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"hardhat-deep-2.0.1.tgz","hashes":{"sha512_sri":"sha512-2JPj1GPPn4tLe4QssJhj6F5T8hHqAEpCqvgoHkZEnMUV/pr1bL+ap3aW+wT5HsZNqJ7SjlG4FrZn3HZZpBWS4A==","sha1":"3bb404b0ad72c15aa11b1e5d1a3998e73007ae08"}}],"evidence_files":[{"path":"index.js","sha256":"4e6c4e61a7019ab0affe9c2d20e36701b330ec357be205930355bac1464f9316","tlsh":"0421149124d560ce9938dac0f6306115acdbc677260752b3bdfc97c927860080161fba"},{"path":"lib/config.js","sha256":"b01c59ae0a76527503799aab109bd701e34f260d192722a8cf12c97a4e6d208c","tlsh":"61265f889244e03796cf1ac3bf0529ede57aa861e4cca30797d4be5cb9ac40bd4b5dd0"},{"tlsh":"68017620deb88e2301ed25424c2a0603b6a58c179528fc2933dba12c0f9d5fb41bf22d","path":"package.json","sha256":"01edd4a40b2c3451b1f0d54d673371e6f02d372239ffa53b6741dd3ab5d80f7f"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}