OpenSSF/OSV advisory MAL-2026-17659 confirms this npm version as malicious. The npm package hardhat-deep@2.0.1 is a trojanised shell. Its tarball copies the pino logger source tree (README, SECURITY.md, index.d.ts, lib/proto.js, lib/transport.js, lib/worker.js, lib/levels.js, lib/multistream.js, etc.) verbatim, while the package name and manifest description target the Hardhat ecosystem. The only novel file is lib/config.js, a single-line 4,499,968-byte obfuscator.io bundle with a...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in hardhat-deep (npm)
Details
The npm package hardhat-deep@2.0.1 is a trojanised shell. Its tarball copies the pino logger source tree (README, SECURITY.md, index.d.ts, lib/proto.js, lib/transport.js, lib/worker.js, lib/levels.js, lib/multistream.js, etc.) verbatim, while the package name and manifest description target the Hardhat ecosystem. The only novel file is lib/config.js, a single-line 4,499,968-byte obfuscator.io bundle with a 26,234-entry rotated string array, two decoder functions, hex-encoded strings and control-flow flattening. The package's top-level index.js is modified from pino's original to unconditionally `require('./lib/config')`, so any consumer that `require`s or `import`s hardhat-deep executes this opaque payload inside the installer's Node process. The exported middleware is a no-op cover with no logger functionality, so running the obfuscated blob is the only effect of installing or loading the package. The author identity (Robert King <hello@jsonspack.com>, jsonspack.com) is unrelated to either Hardhat or pinojs.
Decision reason
OpenSSF Malicious Packages via OSV confirms hardhat-deep@2.0.1 as malicious (MAL-2026-17659): Malicious code in hardhat-deep (npm)