VYPR

npm · Malicious package advisory

Malware

hardhat-node

MAL-2026-1053

Malicious code in hardhat-node (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (64850c9938e9fa6cb3e89f001306cc9906dd810b24573bd990d1cafc92893df2)
The package hardhat-node was found to contain malicious code.

## Source: ossf-package-analysis (a47921f267fec35185f49a67bf28e418adc30a38a6ad5dac536ddf1f1fd2abc7)
The OpenSSF Package Analysis project identified 'hardhat-node' @ 1.0.2 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (2)

  • 1.0.2
  • 1.0.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.