This document describes the management of vulnerabilities for the project and all modules within the organization.
Importing the package runs packed lib/config.js, which fingerprints the host and uses axios plus Function and execSync to fetch and run extra code. Copied Pino files and a no-op middleware hide that dropper.
index.js loads lib/config.js as soon as the package is imported.
index.jsView on unpkg · L4Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkglib/config.js is one packed obfuscated line that builds and runs a Function from decoded strings.
lib/config.jsView on unpkg · L1The package is named hardhat-devkit but uses a stolen Pino vulnerability-policy description and logger keywords, not a Hardhat toolkit.
package.jsonView on unpkg · L2This report applies to hardhat-devkit@2.3.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
index.js loads lib/config.js as soon as the package is imported.
index.jsView on unpkg · L4Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkglib/config.js is one packed obfuscated line that builds and runs a Function from decoded strings.
lib/config.jsView on unpkg · L1The package is named hardhat-devkit but uses a stolen Pino vulnerability-policy description and logger keywords, not a Hardhat toolkit.
package.jsonView on unpkg · L2