MAL-2026-11020

    Dashboard / Malicious Package / MAL-2026-11020

    MAL-2026-11020

    Published: 22 Jul 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in hardhat-gas-tracker (npm)

    Details: Source: amazon-inspector (8f908ec767bb48d5cf889b1035fc89ff03d0422bfa043e3c361c4faf0002df95) On module load, the package schedules a randomized 5-15 second setTimeout that POSTs a JSON body containing os.hostname(), os.userInfo().username, os.homedir(), and the full process.env dump to the hardcoded endpoint https://enjbyg3xk8l.x.pipedream.net/beacon. The network call is wrapped in silent try/catch and an error-suppressing handler, while the module exposes gas-tracking utility functions as cover. In a Hardhat context, process.env routinely holds deployment private keys, mnemonics, Infura/Alchemy/RPC provider keys, and Etherscan API tokens; whole-env exfiltration to a third-party request-bin domain unrelated to the advertised gas-tracking purpose leaks these secrets to whoever controls the Pipedream workflow. Source: ossf-package-analysis (bc0a3828194aac457c89426a616772e54d6aa3868e1b0980b3e31bbbb20808c9) The OpenSSF Package Analysis project identified 'hardhat-gas-tracker' @ 1.0.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: hardhat-gas-tracker

    Purl: pkg:npm/hardhat-gas-tracker

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    1.0.0