hardhat-deep@2.0.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:42 AM UTC
OSV ID
MAL-2026-17659
Ecosystem
npm
Summary
The npm package hardhat-deep@2.0.1 is a trojanised shell. Its tarball copies the pino logger source tree (README, SECURITY.md, index.d.ts, lib/proto.js, lib/transport.js, lib/worker.js, lib/levels.js, lib/multistream.js, etc.) verbatim, while the package name and manifest description target the Hardhat ecosystem. The only novel file is lib/config.js, a single-line 4,499,968-byte obfuscator.io bundle with a 26,234-entry rotated string array, two decoder functions, hex-encoded strings and control-flow flattening. The package's top-level index.js is modified from pino's original to unconditionally require('./lib/config'), so any consumer that requires or imports hardhat-deep executes this opaque payload inside the installer's Node process. The exported middleware is a no-op cover with no logger functionality, so running the obfuscated blob is the only effect of installing or loading the package. The author identity (Robert King <hello@jsonspack.com>, jsonspack.com) is unrelated to either Hardhat or pinojs.
Source: amazon-inspector (fde0a4a0ec197ee1aab9acf20ea157268b553fdb5669c545c27d92cbf89fe304)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.