{"id":"MAL-2026-17636","summary":"Malicious code in hardhat-init (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e2f570102756d04aa466677488cd13aacac2eb941176523bc4ff024d214affbb)\nThe npm package hardhat-init presents itself as Hardhat initialization tooling and ships a README, LICENSE, and index.d.ts copied from the pino logger project with the name substituted. The main entry index.js requires./lib/config at the top level, which triggers a ~4.3MB heavily obfuscated JavaScript file (lib/config.js) whose top-level IIFE executes immediately on module load. The obfuscation uses hex-escaped string tables, nested index-lookup helpers, and a string-array shuffler consistent with obfuscator.io output, with no plaintext surface describing the behavior. The exported index.js is a trivial no-op that does not consume anything from lib/config, so the sole effect of loading the package is to execute the opaque payload. The combination of a name/content mismatch (hardhat-init vs. copied pino scaffolding), an oversized obfuscated sibling file with no legitimate purpose for an init helper, and auto-execution on require is a typosquat loader shape that causes arbitrary attacker-controlled code to run on the installer's machine the first time any consumer imports the package.\n","modified":"2026-10-06T05:00:08.055881754Z","published":"2026-10-06T04:27:56Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["2.21.0"],"id":"IN-MAL-2026-021097","import_time":"2026-10-06T04:47:23.612749357Z","modified_time":"2026-10-06T04:27:56Z","sha256":"e2f570102756d04aa466677488cd13aacac2eb941176523bc4ff024d214affbb"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/hardhat-init/v/2.21.0"}],"affected":[{"package":{"name":"hardhat-init","ecosystem":"npm","purl":"pkg:npm/hardhat-init"},"versions":["2.21.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"hardhat-init-2.21.0.tgz","hashes":{"sha1":"d16463c24940a68741391ca525069c47fc0a8fd5","sha512_sri":"sha512-JgEysB5pN15esOUR2q9dI60yi2QubOXAtoXaqDwLivNfpjAvipaveC8Fh+S11Ryvy92GtuAMP7PPtfMZr0wk6w=="}}],"evidence_files":[{"path":"lib/config.js","sha256":"7e4c6d76f1d845f752e37876a2d3f773996719f33c2d1c282e0a84b04444efeb","tlsh":"bf1694889194e02b96df1753bf052afdd13aa876d0cca747c2d4be9d29ac80be475cd0"},{"sha256":"cdf26c22ebf462aad3fbcec145f0522ef33d7cc597bdfb1eeb9e93061c121c84","tlsh":"8a017620deb88e2301ed25524c2a0643ba658c175528fc2932dba12c0fad5fb01bf21d","path":"package.json"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hardhat-init/MAL-2026-17636.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}