Malicious npm packages target Ethereum developers, impersonating Hardhat plugins to steal private keys and sensitive data.Researchers have discovered a supply chain attack targeting the Nomic Foundation and Hardhat platforms, using malicious npm packages.Twenty malicious packages impersonating Hardhat have been identified with over one thousand downloads.Attackers steal private keys and configuration details, emphasizing the need for stricter auditing tools.