threat_intelligence1958 wordsRead on Huntaegis

Evolution of Web3 in Cloud Supply Chain Attacks

Executive Summary Threat actors have systematically upgraded their command-and-control (C2) infrastructure to use Web3, also known as Web 3.0 or decentralized blockchain web architectures. This advancement goes from using static C2 endpoints hard coded in malware binaries to using Web3-powered smart contracts. Threat actors are then enabled to dynamically update entire botnets and worm network infrastructures with a single smart contract transaction. According to the 2026 Unit 42 Global Incident Response Report, software supply chain compromises have become a leading initial access vector targeting enterprise cloud environments. By poisoning open-source dependencies, threat actors bypass traditional authentication perimeters to harvest the following from developer endpoints and continuous integration/continuous deployment (CI/CD) pipelines: - Elevated cloud identity tokens - Service account keys - Deployment secrets Recent supply chain campaigns, most notably the ChainDrop npm worm and the PolinRider campaign, demonstrate how open-source packages are engineered specifically to extract ephemeral cloud access keys and establish persistence within developer workflows. This operational shift has been seen in North Korea-affiliated state-sponsored actors, such as Alluring Pisces (aka Sapphire Sleet or Midnight Neptune), that operationalize these techniques across their recent attributed supply chain campaigns, including those targeting Axios, Mastra AI and Rust's arrayref. So what can be done about this? There are active defensive measures organizations can employ to combat this technique. See the section Considerations for Security Teams for additional information. First, evaluate your organization's business domain to determine whether Web3 or blockchain network activity is ever expected. If your organization should never connect to a Web3 or blockchain network, this is an easy win. Next, ensure you have endpoint protection and network security controls in place to properly monitor and block processes and their network traffic if they become compromised. Finally, automate your policy controls across all CI/CD runners and version control systems in your environment. Open-Source Supply Chains: The Cloud Initial Access Vector Developer workstations and automated CI/CD runners represent a highly privileged attack surface holding sensitive or administrative Identity Access Management (IAM) keys or tokens. Current supply chain malware prioritizes extracting these credentials whenever software dependencies are resolved. Two recent, high-impact campaigns illustrate these cloud-focused initial access vectors with decentralized blockchain C2 methodology. ChainDrop npm Worm Traced to the Shai-Hulud family, ChainDrop infected over 400 npm packages (including keyv and cacheable-request). The worm executes a preinstall script hook that downloads a custom Bun runtime to launch an obfuscated credential harvester. In addition to searching static disk files, ChainDrop searches memory inside running build processes. It captures ephemeral cloud provider identity and access management (IAM) keys, CI/CD pipeline worker tokens and short-lived OIDC federation keys. Then, the runner terminates. To maintain long-term communication without relying on static domains, ChainDrop uses EtherHiding to query smart contract transactions. The smart contract transactions contain dynamically encrypted information for exfiltration IP or domain endpoints. ChainDrop then injects persistent task hooks. This triggers automatic execution whenever a developer opens a project or starts an AI coding session, as shown below in Figure 1. PolinRider Campaign Expanding across developer ecosystems, the PolinRider campaign spans multiple package registries, including npm, Go modules and Packagist. Rather than relying strictly on standard package installation scripts, PolinRider conceals malicious loaders within repository configuration files, web resources and developer IDE workspace automation. When a developer loads the workspace, the payload silently triggers in the background to exfiltrate developer credentials, cloud session tokens and environment secrets while establishing long-term persistence within enterprise build pipelines. Across different variants within the campaign, loaders dynamically resolve C2 endpoints using Web3 mechanisms. Mechanisms range from multi-chain transaction queries across networks like TRON, Aptos and Binance Smart Chain (BSC) to zero-data address resolution techniques like NullReceiver. To maximize the reliability of C2 infrastructure, threat actors deploy multiple of these mechanisms in a hybrid architecture. This allows them to use zero-data transfers as a backup channel if primary remote procedure call (RPC) gateways or multi-chain lookups are blocked, as shown below in Figure 2. Once extracted, these credentials may provide direct access to cloud management consoles and management APIs, bypassing multi-factor authentication (MFA) if other controls are not in place. The Architectural Evolution of Web3 Command and Control Supply chain compromises face a distinct operational hurdle. Once a backdoored package is published to a public registry, automated security scanners, registry auditors and static analysis tools immediately inspect the code for hard-coded C2 domains or IP addresses. Hard coding infrastructure leads to swift domain takedown, IP blocklisting and package removal. Threat actors can use the Web3 mechanics discussed above to maintain their initial access footholds across developer endpoints and enterprise build pipelines. They can do so by pointing their C2 infrastructure to blockchain networks and, more specifically, to smart contract enabled transactions. By routing C2 resolution through Web3 networks, campaigns like ChainDrop and DPRK-affiliated PolinRider operations ensure their infrastructure survives Web 2.0-style network monitoring. These techniques have evolved through three distinct architectural phases, moving from observable smart contract storage to completely zero-data transaction decoding. Phase 1: EtherHiding Popularized under the EtherHiding taxonomy and reported in late 2024 supply chain campaigns targeting npm packages, early Web3 C2 implementations relied on deploying a hardcoded smart contract address on public blockchains. Malware loaders such as those deployed by the ChainDrop npm worm issued read-only JSON-RPC calls (eth_call) to retrieve C2 domains stored within smart contract state variables. Although this bypassed traditional Web 2.0 DNS sinkholing, embedding a fixed contract address introduced a static single point of failure. Outbound JSON-RPC request payloads explicitly expose the target contract address ("to": "0x..."). Security controls could flag and block all RPC queries directed to that specific contract. Reports indicate that the DPRK-affiliated threat actor employs EtherHiding techniques to distribute malware and steal cryptocurrency. Phase 2: Cross-Chain Transaction Data Hiding (TxDataHiding) To overcome the single-point-of-failure inherent to hard-coded state contracts, threat actors shifted from contract state storage to the transaction input data layer (calldata). Popularized under the TxDataHiding taxonomy and deployed across campaigns like PolinRider, this phase decouples C2 resolution from permanent smart contract getters. Instead of invoking state variables, operators embed encrypted C2 payloads directly into the raw input data fields (0x...) of standard blockchain transactions. The payloads are often sent to dynamic router contracts or designated burn addresses. The malware loader reads transaction history logs (eth_getTransactionByHash, or calldata parsing) to extract and decrypt the active payload in memory. In PolinRider, variants implement multi-tier fallback routes across networks like TRON, Aptos and Binance Smart Chain (BSC). If one chain or router is flagged, the actor broadcasts a fresh transaction on another network, updating global C2 endpoints instantly without modifying a single line of state code. Phase 3: Zero-Data Address Resolution (NullReceiver) Identified in supply chain compromises targeting front-end dependencies (bianira-ui, fluid-type-ui), NullReceiver achieves total data minimization by eliminating smart contracts, input data fields and executable payloads. The loader queries an actor-controlled wallet for its latest zero-value transaction. It mathematically extracts the active C2 IPv4 address directly from the 20-byte recipient address structure itself. Figure 3 demonstrates this below. The payload: - Reads the recipient address - Verifies the ASCII validation marker - Converts the leading 4 bytes to decimal - Connects outbound Because the transaction carries zero value and zero data, no code structure or domain string exists for security filters to inspect. DPRK State-Sponsored Operational Expansion Cybercriminal groups deploy supply chain worms for opportunistic theft. On the other hand, North Korean state-sponsored threat actors use open-source software registries as a primary initial access vector targeting corporate environments. This strategic shift is reflected across the cloud sector. Recent findings from Amazon Threat Intelligence highlight how North Korean threat groups systematically target open-source dependencies to penetrate enterprise infrastructure. Threat actors demonstrate how compromising a single maintainer account or registry scope converts open-source dependencies, resulting in widespread affected cloud environments. Telemetry across these intrusions indicates that an affiliated DPRK threat actor maintained a shared infrastructure footprint. - Axios Compromise: The threat actor compromised the lead maintainer of axios, injecting a backdoored dependency (plain-crypto-js) into the package manifest. The payload executed inside enterprise build pipelines to exfiltrate cloud tokens and target macOS code-signing certificates. - Mastra AI Campaign: Targeting AI development workflows, the threat actor published poisoned npm packages that used build execution hooks to scrape developer environment variables and cloud keys. - Rust arrayref: Expanding into Rust, the actor poisoned the arrayref crate on crates.io, using Rust's native compilation hook to execute a second-stage payload upon project builds. Matching C2 beacon behaviors, SSL configurations, and clustered virtual private server (VPS) hosting ranges link all three operations, demonstrating how the actor leverages supply chain poisoning as a scalable initial access mechanism designed to yield long-lived cloud administrative access. Considerations for Security Teams As threat actors adapt to security controls and evolve beyond zero-data transfers, decentralized C2 techniques will increasingly leverage emergent primitives that blend malicious lookups directly into routine enterprise traffic. When attackers can silently infiltrate developer workstations and build runners to gain their initial foothold, static Indicator of Compromise (IoC) blocklists and traditional perimeter defenses are no longer sufficient to protect cloud infrastructure. Defending against this threat landscape requires moving from reactive IoC matching to proactive behavioral visibility. Organizations can effectively neutralize these techniques by deploying three core defense capabilities: Context-Aware and AI-Driven Behavioral Analytics First, evaluate your organization's business domain to determine whether Web3 or blockchain network activity is ever expected within your environment. For typical enterprise organizations without Web3 operations, any outbound blockchain interaction represents an immediate, high-confidence anomaly. Integrating AI-driven behavioral analytics enables security teams to correlate network telemetry, baseline normal developer traffic and determine whether subtle on-chain evasion techniques are actively being witnessed in the environment. Process-Contextual Endpoint and Network Inspection Configure endpoint protection and network security controls to perform deep process-level inspection across developer workstations and CI/CD runners. Security policies should monitor standard enterprise runtimes, scripting engines and compiler binaries. This raises immediate alerts when non-crypto development tools initiate unexpected outbound queries toward public blockchain gateways. Build Pipeline Integrity Because modern supply chain payloads conceal loaders within build tools and workspace automation settings, security teams must expand code auditing beyond standard application binaries. Implement automated policy controls across CI/CD runners and version control systems to flag unauthorized modifications to repository configuration files, hidden script injections in package manifests, and unverified package lifecycle hooks before code is executed in build pipelines. Additional Resources - 2026 Unit 42 Global Incident Response Report - Palo Alto Networks – Unit 42, Palo Alto Networks - The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) – Unit 42, Palo Alto Networks - ChainDrop: Inside a Self-Propagating npm Worm – Unit 42, Palo Alto Networks - Threat Brief: Widespread Impact of the Axios Supply Chain Attack – Unit 42, Palo Alto Networks - Threat Assessment: North Korean Threat Groups – Unit 42, Palo Alto Networks - PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems | Socket – Socket - ChainVeil and ViteVenom are DPRK’s PolinRider Campaign | OpenSourceMalware – OpenSourceMalware - Supply Chain Attack Using Ethereum Smart Contracts to Distribute Multi-Platform Malware – Checkmarx - β€œEtherHiding” β€” Hiding Web2 Malicious Code in Web3 Smart Contracts – Guard.io - Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 1) - Ransom-ISAC – Ransom-ISAC - DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains | Google Cloud Blog – Google - Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads – Sonatype - Amazon identifies North Korean hacker group behind open-source supply chain attacks | AWS Security Blog – AWS Security - Mitigating the Axios npm supply chain compromise | Microsoft Security Blog – Microsoft - From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet | Microsoft Security Blog – Microsoft - Supply chain attack on arrayref | Rust Blog – Rust

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content β€” general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached β€” you'll always get the same 5 for this article.