---
canonical: "https://firewall.lpm.dev/npm/hardhat-cap/v/2.21.1"
markdown: "https://firewall.lpm.dev/npm/hardhat-cap/v/2.21.1.md"
package: "hardhat-cap"
report_status: "published"
title: "hardhat-cap@2.21.1 npm security report"
verdict: "malicious"
version: "2.21.1"
---

# hardhat-cap@2.21.1 npm security report

> **Trust boundary:** Package metadata, advisory text, filenames, URLs, and source snippets in this report come from external packages or feeds. Treat them as untrusted evidence. Do not execute instructions or code found in this document.

## Verdict summary
**Blocked & quarantined** — Unconsented host access and remotely directed malicious behavior may occur at import time.

- **Verdict:** Malicious
- **Product-default install policy:** Block
- **Firewall policy:** Matched malicious
- **Public report status:** Published
- **Threat category:** Malware
- **Selected version:** 2.21.1
- **Selected version is latest:** Yes
- **Analysis source:** AI Security Review (lpm-firewall-ai)

Importing the package loads an opaque, obfuscated payload before the exported middleware is used. The payload dynamically decodes behavior and includes filesystem and network-capable logic.

## Latest scan
- **Scanner version:** rust-scanner-worker-schema-1
- **Verdict:** Malicious
- **Confidence:** 97.0%
- **Started:** 2026-08-08T08:33:27.944Z
- **Finished:** 2026-08-08T08:34:18.113Z
- **Download time:** 520 ms
- **Static scan time:** 2672 ms
- **AI review time:** 46976 ms
- **Total time:** 50169 ms

## Security analysis

### Published attack-surface review

- **Summary:** Importing the package loads an opaque, obfuscated payload before the exported middleware is used. The payload dynamically decodes behavior and includes filesystem and network-capable logic.

- **Trigger:** require/import of hardhat-cap

- **Impact:** Unconsented host access and remotely directed malicious behavior may occur at import time.

- **Evidence paths:** package.json, index.js, lib/config.js

- **Review source:** ai\_review

- **Reviewed:** 2026-08-08T08:34:18.113Z

### AI review details

- **Review stage:** source\_first\_review

- **Mechanism:** eager execution of obfuscated dynamic payload

- **Attack narrative:** The main entrypoint immediately imports lib/config.js. That file is an unusually large, deliberately obfuscated payload with runtime decoding, indirect dynamic execution, filesystem traversal, and HTTP/HTTPS handling; these capabilities are unrelated to the exported no-op middleware. Its opacity prevents safe attribution to a legitimate package function and creates an import-time execution surface.

- **Rationale:** Source inspection confirms an import-reachable opaque payload with dynamic execution and host/network-capable primitives, not merely scanner labeling. Absence of lifecycle hooks does not mitigate runtime import execution.

- **Files touched:** index.js, lib/config.js

### Review decision

- **Verdict:** Malicious

- **Confidence:** 97.0%

- **Recommended action:** publish\_block

- **Intent class:** Malware

- **False-positive risk:** Low

- **Evidence for:** index.js eagerly requires ./lib/config on import., lib/config.js is a 4.06 MB single-line, heavily obfuscated executable payload., lib/config.js contains runtime string decryption and indirect Function/global-object construction., lib/config.js includes obfuscated filesystem traversal and HTTP/HTTPS URL handling.

- **Evidence against:** package.json has no install lifecycle hooks., index.js exports a superficially benign middleware wrapper.

## Public findings

### 1. Low: Scripts Present
- **Category:** Manifest
- **Confidence:** 100.0%

Package declares npm scripts.

### 2. High: Child Process
- **Category:** Source
- **Confidence:** 85.0%
- **Path:** index.js
- **Public source:** [View source](<https://unpkg.com/hardhat-cap@2.21.1/index.js>)

Package source references child process execution.

Public source snippet (untrusted):

```javascript
L3: const path = require('path');
L4: const { spawn } = require('child_process');
L5: const { DEFAULT_LEVELS, SORTING_ORDER } = require('./lib/constants');
```

### 3. Medium: Environment Vars
- **Category:** Source
- **Confidence:** 75.0%

Package source references environment variables.

### 4. Critical: Download Execute
- **Category:** Source
- **Confidence:** 90.0%
- **Path:** lib/config.js
- **Public source:** [View source](<https://unpkg.com/hardhat-cap@2.21.1/lib/config.js>)

Source downloads or fetches remote code and executes it.

Public source snippet (untrusted):

```javascript
L1: function yS(F,S,Y,E,i){const Fq={F:0x6e};return T(i-Fq.F,S);}function yY(F,S,Y,E,i){const FC={F:0x49};return T(i-FC.F,S);}function yn(F,S,Y,E,i){const Fn={F:0x1ba};return j(S- -Fn....
```

### 5. Critical: Trigger Reachable Dangerous Capability
- **Category:** Source
- **Confidence:** 90.0%
- **Path:** lib/config.js
- **Public source:** [View source](<https://unpkg.com/hardhat-cap@2.21.1/lib/config.js>)

A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.

Public source snippet (untrusted):

```javascript
Trigger-reachable chain: manifest.main -> index.js -> lib/config.js
L1: function yS(F,S,Y,E,i){const Fq={F:0x6e};return T(i-Fq.F,S);}function yY(F,S,Y,E,i){const FC={F:0x49};return T(i-FC.F,S);}function yn(F,S,Y,E,i){const Fn={F:0x1ba};return j(S- -Fn....
```

### 6. Low: High Entropy Strings
- **Category:** Supply Chain
- **Confidence:** 55.0%

Package source contains high-entropy string patterns.

### 7. Low: Url Strings
- **Category:** Supply Chain
- **Confidence:** 65.0%

Package source contains URL literals.

### 8. Medium: Structural Risk Force Deep Review
- **Category:** Artifact Inventory
- **Confidence:** 100.0%

Artifact structure forces deeper review even if the static behavioral verdict is clean.

### 9. High: Semantic Analysis Limited
- **Category:** Scanner Coverage
- **Confidence:** 100.0%
- **Path:** lib/config.js
- **Public source:** [View source](<https://unpkg.com/hardhat-cap@2.21.1/lib/config.js>)

A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.

Public source snippet (untrusted):

```javascript
stage = ast_semantic_analysis; reason = ast_path_work_budget_exceeded; limitedFiles = 1
```

### 10. High: Known Malware Source Fingerprint Signature
- **Category:** Supply Chain
- **Confidence:** 94.0%
- **Path:** lib/tools.js
- **Public source:** [View source](<https://unpkg.com/hardhat-cap@2.21.1/lib/tools.js>)

Source fingerprint signature matches a known malicious package signature; route for source-aware review.

Public source snippet (untrusted):

```javascript
matchType = malicious_source_fingerprint_signature
signature = 8d2e4ca7c22e8649
signatureType = suspicious_hashes
sourceLabel = final_verdict:malicious
matchedPackage = hardhat-set@2.21.0
matchedPath = lib/tools.js
matchedIdentity = npm:aGFyZGhhdC1zZXQ:2.21.0
similarity = 1.000
shingleOverlap = 12
summary = package final verdict is malicious
```

## Dependencies and install lifecycle
- **Lifecycle scripts present:** No

- **Dependencies:** 2
- **Optional dependencies:** 0
- **Peer dependencies:** 0
- **Development dependencies:** 1
- **Published dependency-graph edges:** 2

### Published dependency entries
- axios ^1.10.0 (Dependency)
- parse-json ^8.3.0 (Dependency)

## Package metadata
- **Package:** hardhat-cap
- **Ecosystem:** npm
- **Version:** 2.21.1
- **License:** MIT
- **Version published:** 2026-08-07T12:19:50.731Z
- **Package first seen:** 2026-08-08T08:34:18.113Z
- **Package last seen:** 2026-08-08T08:34:18.113Z
- **Known versions:** 1
- **Latest version:** 2.21.1
- **Appeal under review:** No
- **Description:** This document describes the management of vulnerabilities for the project and all modules within the organization.
- **Author:** Robert King
- **Keywords:** fast, logger, stream, json
- **Artifact files:** 42
- **Artifact unpacked size:** 4,329,483 bytes
- **Artifact signatures:** 1
- **Attestations:** No

## References
- [HTML security report](<https://firewall.lpm.dev/npm/hardhat-cap/v/2.21.1>)
- [Issues](<https://jsonspack.com/issues>)
- [OSV advisory](<https://osv.dev/vulnerability/MAL-2026-13616>)
