Security1 publisherNot yet confirmed elsewhere2 min readPublished
Unit 42 finds supply-chain malware fetching its C2 addresses from blockchain smart contracts
Unit 42 says supply-chain attackers have moved command-and-control into blockchain smart contracts, so one transaction can re-point an entire botnet or worm. Defenders' useful choke points are now developer machines, CI runners and the chain lookup itself.
The Watch · Security desk

What happened
- ChainDrop, a worm Unit 42 traces to the Shai-Hulud family, infected more than 400 npm packages, including keyv and cacheable-request.
- Inside running build processes, the worm searches memory for ephemeral cloud IAM keys, CI/CD worker tokens and short-lived OIDC federation keys.
- PolinRider spans npm, Go modules and Packagist, hiding loaders in repository config files, web resources and IDE workspace automation.
- Across variants, PolinRider's loaders resolve C2 through transaction queries on TRON, Aptos and Binance Smart Chain, or through zero-data address tricks such as NullReceiver.
- Unit 42 says North Korea-linked Alluring Pisces uses these techniques in attributed campaigns targeting Axios, Mastra AI and Rust's arrayref.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Indicator feeds built from one sample's exfiltration domains lose value as soon as the operator posts a new transaction to the contract.
- cost Cleanup reaches past uninstalling a package, because ChainDrop's injected task hooks rerun whenever a developer opens a project or starts an AI coding session.
- exposure Developer machines and CI runners holding administrative IAM keys become the way into cloud accounts at the moment they resolve a poisoned dependency.
- precedent A state-sponsored group running the method across several attributed campaigns makes it established tradecraft, so further supply-chain campaigns with chain-hosted C2 are the expected next step.
Older implants carried their command server in the binary, as a domain or IP address the author hardcoded [2]. ChainDrop carries a lookup instead. Through EtherHiding, it queries smart contract transactions that hold encrypted exfiltration IPs or domains [9]. A server still receives the stolen keys. Its address sits on a chain, and Unit 42 says a single smart contract transaction can update the infrastructure behind an entire botnet or worm [3].
The lookup is still network traffic to a blockchain. Unit 42's first recommendation is to establish whether Web3 or blockchain activity is ever expected in the business [14]. "If your organization should never connect to a Web3 or blockchain network, this is an easy win," Unit 42 wrote [19]. PolinRider makes that filter harder to write. Its variants spread their queries across more than one chain [13], so a rule covering one network leaves the others reachable [21].
Where blockchain traffic has a legitimate use, the controls move to the host. Unit 42 recommends endpoint and network controls that can monitor and block a process and its traffic once it is compromised [15]. It also recommends automated policy across every CI/CD runner and version control system [16]. Entry points differ by campaign. ChainDrop starts from a preinstall script hook that downloads a custom Bun runtime to launch its harvester [7]. PolinRider does not rely strictly on standard install scripts [18] and fires when a developer loads the workspace [12]. A control that blocks install-time scripts would interrupt ChainDrop's entry and miss PolinRider's [20].
The attacker leaves with cloud access. According to Unit 42, poisoned dependencies yield elevated cloud identity tokens, service account keys and deployment secrets from developer endpoints and CI/CD pipelines [5]. PolinRider also sets up long-term persistence inside enterprise build pipelines [12]. Unit 42's 2026 Global Incident Response Report names software supply chain compromise as a leading initial access vector into enterprise cloud environments [4].
What to watch
- Whether Unit 42 or another researcher ties ChainDrop or PolinRider to Alluring Pisces, which would put a state actor behind the 400-plus infected npm packages.
- Growth in ChainDrop's infected-package count past 400, or PolinRider loaders appearing in registries beyond npm, Go modules and Packagist.
- Publication of the contract addresses ChainDrop and PolinRider query, which would give defenders specific lookups to alert on.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption45
- Hype gap+15
- Incentives45
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
North Korea-affiliated state-sponsored actor Alluring Pisces (aka Sapphire Sleet or Midnight Neptune) operationalizes these techniques across its recent attributed supply chain campaigns, including those targeting Axios, Mastra AI and Rust's arrayref.
- [2]
According to Unit 42, threat actors have systematically upgraded C2 infrastructure from static endpoints hardcoded in malware binaries to Web3-powered smart contracts.
- [3]
Smart contract C2 enables threat actors to dynamically update entire botnets and worm network infrastructures with a single smart contract transaction.
- [4]
According to the 2026 Unit 42 Global Incident Response Report, software supply chain compromises have become a leading initial access vector targeting enterprise cloud environments.
- [5]
By poisoning open-source dependencies, threat actors harvest elevated cloud identity tokens, service account keys and deployment secrets from developer endpoints and CI/CD pipelines.
- [6]
ChainDrop, traced to the Shai-Hulud family, infected over 400 npm packages, including keyv and cacheable-request.
- [7]
ChainDrop executes a preinstall script hook that downloads a custom Bun runtime to launch an obfuscated credential harvester.
- [8]
ChainDrop searches memory inside running build processes and captures ephemeral cloud provider IAM keys, CI/CD pipeline worker tokens and short-lived OIDC federation keys.
- [9]
ChainDrop uses EtherHiding to query smart contract transactions that contain dynamically encrypted information for exfiltration IP or domain endpoints.
- [10]
ChainDrop injects persistent task hooks that trigger automatic execution whenever a developer opens a project or starts an AI coding session.
- [11]
The PolinRider campaign spans npm, Go modules and Packagist and conceals malicious loaders within repository configuration files, web resources and developer IDE workspace automation.
- [12]
When a developer loads the workspace, the PolinRider payload exfiltrates developer credentials, cloud session tokens and environment secrets while establishing long-term persistence within enterprise build pipelines.
- [13]
Across PolinRider variants, loaders resolve C2 endpoints using Web3 mechanisms ranging from multi-chain transaction queries across TRON, Aptos and Binance Smart Chain to zero-data address resolution techniques such as NullReceiver.
- [14]
Unit 42's first recommendation is to evaluate the organization's business domain to determine whether Web3 or blockchain network activity is ever expected.
- [15]
Unit 42 recommends endpoint protection and network security controls to monitor and block processes and their network traffic if they become compromised.
- [16]
Unit 42 recommends automating policy controls across all CI/CD runners and version control systems.
- [17]
Developer workstations and CI/CD runners hold sensitive or administrative IAM keys or tokens, and current supply chain malware prioritizes extracting these credentials whenever software dependencies are resolved.
- [18]
PolinRider does not rely strictly on standard package installation scripts.
- [19]
"If your organization should never connect to a Web3 or blockchain network, this is an easy win."
- [20]
A control that blocks install-time package scripts would interrupt ChainDrop's preinstall entry point but would not stop PolinRider's workspace-triggered loaders.
- [21]
A blockchain egress rule covering only one network leaves PolinRider variants that query other chains able to resolve C2.
Sources
1 independent publisher whose own reporting we read for this story.
- unit42.paloaltonetworks.comEvolution of Web3 in Cloud Supply Chain Attacks
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Blockchain-Based Command and ControlFollow
- Software Supply Chain SecurityFollow
- CI/CD Pipeline SecurityFollow
- North Korean Cyber OperationsFollow