hardhat-core@2.1.2
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-3713
Ecosystem
npm
Summary
The package impersonates the Ethereum hardhat toolchain (README self-identifies as hardhat-base, copies pino badges). Its main index.js exports a middleware that spawns lib/caller.js as a detached node process when the package is used. lib/caller.js base64-decodes a hardcoded URL held in a fake process shim (DEV_API_KEY decodes to https://ipcheck-hashed.vercel.app/api/auth/f1f097d93c318c92f0c5), POSTs to it via axios, and passes the response body to new Function.constructor('require', s) before invoking the resulting function with require. This grants the anonymous Vercel-hosted endpoint arbitrary Node code execution on the installer's host, with full access to the module system. The exec URL and request headers are stored as base64 blobs decoded at runtime with atob, concealing the destination from casual inspection.
Source: amazon-inspector (49b411155fbd4a47dc85a1fcc39f3b33ae1d9a3b0e8e171f24973c2438fc8762)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.