Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-17236 confirms this npm version as malicious. mini-hardhat@1.1.4 presents itself as a pino-like JSON logger, but its main entry exports a middleware factory that, on instantiation, spawns lib/caller.js as a detached, stdio-ignored, unref'd child process so execution survives the parent. lib/caller.js base64-decodes a hardcoded URL (stored under decoy keys named DEV_API_KEY/DEV_SECRET_KEY/DEV_SECRET_VALUE) resolving to...
This report applies to mini-hardhat@1.1.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.