OpenSSF/OSV advisory MAL-2026-17233 confirms this npm version as malicious. The npm package hardhat-lock@2.21.0 publishes itself as a logger/middleware but its identity and contents are inconsistent with that purpose: README badges, LICENSE, index.d.ts and docs/* are copied from the unrelated pino project (maintained by pinojs), while the package name squats the Ethereum-tooling keyword 'hardhat'. index.js unconditionally executes require('./lib/config') at module load, and lib/config.js is...
This report applies to hardhat-lock@2.21.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.