Skip to content

Topic

Blockchain-Resolved Command and Control

A C2 technique where malware resolves controller addresses via decentralized systems like Ethereum Name Service or Tor, evading takedown efforts.

Current stories

build1 publisher

Poisoned vite.config.js turns git pull and npm run build into malware

Malware that steals a developer's Git credentials force-pushes a poisoned vite.config.js to every reachable branch, a dozen rewritten in a minute in one case. A routine git pull and build then runs it, and dependency scanners never see the change.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
security4 publishers

Dark Caracal's Ethereum fallback moves C2 recovery off the names defenders can seize

Arctic Wolf links a June 2026 intrusion in Venezuela to a new Go framework whose extended build reads replacement C2 addresses from a smart contract, and says the feature has been used.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 57%
Investor
Investor 9%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives40
Confidence58
security3 publishers

Malicious npm package indexed-btree fires its loader from a runtime library call

Checkmarx says a fake sorted-btree clone reached 2 million weekly downloads with clean install scripts, starting its loader only when an application calls BTree.prototype.set with a particular key. Nine related packages have been pulled.

Perspective Coverage

3 publishers
Builder
Builder 43%
Operator
Operator 45%
Investor
Investor 12%

Reality

Evidence62
Adoption45
Hype gap+20
Incentives45
Confidence60