Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Methodology note: This article is based on the Unit 42 report dated October 7, 2026, the sole structured primary source available; independent corroboration was not possible. The date 2026-10-07 is reported by the primary source without further temporal context.
Threat actors have systematically upgraded command-and-control infrastructure to use Web3 and decentralized blockchain smart contracts. The Unit 42 report documents two campaigns — ChainDrop and PolinRider — that demonstrate the shift from static C2 endpoints to dynamic exfiltration mechanisms. The cloud software supply chain is the entry point: open-source registries distribute the malware, while smart contracts and blockchain transactions handle remote control.
- The ChainDrop campaign infected over 400 npm packages, including keyv and cacheable-request, using EtherHiding on Ethereum to dynamically distribute exfiltration endpoints.
- PolinRider extends the attack to npm, Go modules, and Packagist with loaders hidden in configuration files, web resources, and IDE automations, resolving C2 via multi-chain TRON, Aptos, Binance Smart Chain, and zero-data NullReceiver techniques.
- ChainDrop hunts for cloud IAM credentials, CI/CD worker tokens, and OIDC federation keys in build-process memory as well as on disk, with direct access to cloud management consoles and APIs.
- Threat actors deploy hybrid architectures with multiple Web3 C2 techniques and zero-data backup channels to maximize reliability.
Facts from the Report: How Web3 C2 Works
Unit 42 reports that threat actors "have systematically upgraded their command-and-control (C2) infrastructure to use Web3, also known as Web 3.0 or decentralized blockchain web architectures." The documented shift goes "from using hard-coded static C2 endpoints in malware binaries to using Web3-based smart contracts." This allows them to "dynamically update entire botnets and worm infrastructures with a single smart contract transaction."
The report identifies two campaigns that demonstrate this evolution.
ChainDrop (Shai-Hulud family) infected over 400 npm packages. The malware uses EtherHiding to query smart contract transactions on Ethereum containing "dynamically encrypted information for IP or domain exfiltration endpoints." ChainDrop searches for "ephemeral cloud provider IAM keys, CI/CD pipeline worker tokens, and short-lived OIDC federation keys" in build-process memory as well as on disk. Extracted credentials provide direct access to cloud management consoles and APIs, bypassing MFA if other controls are absent. ChainDrop "injects persistent task hooks that trigger on project opening or AI coding session startup."
PolinRider extends across npm, Go modules, and Packagist with loaders hidden in repository configuration files, web resources, and IDE workspace automation. The loaders "dynamically resolve C2 endpoints using Web3 mechanisms," with "multi-chain queries on networks such as TRON, Aptos, and Binance Smart Chain (BSC)" and "zero-data address resolution techniques like NullReceiver." The actors "deploy multiple of these mechanisms in a hybrid architecture" and "use zero-data transfers as a backup channel."
"Threat actors have systematically upgraded their command-and-control (C2) infrastructure to use Web3, also known as Web 3.0 or decentralized blockchain web architectures" — Unit 42, 'Evolution of Web3 in Cloud Supply Chain Attacks'
Editorial Analysis: The Decentralization Paradox
The report positions the campaigns in a broader trend. The '2026 Unit 42 Global Incident Response Report' indicates that software supply chain compromises have become the primary initial access vector for enterprise cloud environments. Contextual data from the same report — not directly linked to the Web3 C2 campaigns — signals that AI-driven attacks are 4x faster in moving from initial access to exfiltration, that 65% of initial access occurs via identity-based techniques, and that 87% of attacks span multiple surfaces.
The documented evolution raises a structural paradox. The properties that make blockchain censorship-resistant — immutability, lack of central authority, permissionless access — are the same ones that prevent blocking it as a C2 channel. Enterprise security systems are designed to detect malicious domains and IPs, not to analyze smart contract transactions. The traditional perimeter does not extend to the blockchain.
The separation between layers is critical for understanding. Open-source registries (npm, Go modules, Packagist) are the entry vector: they distribute the malicious code. The blockchain is the persistence and control layer: it updates C2 channels after initial infection. Conflating the two risks masking the two-phase nature of the attack.
What Changes
The report contains no specific operational recommendations. Implications are inferred from the documented mechanisms.
Traditional security scanners detect hard-coded domains and IPs but cannot block blockchain smart contracts used for C2. This is an architectural limitation, not a temporary gap. The ability to update entire botnets with a single transaction eliminates the time window between detecting an endpoint and its replacement: there is no longer an endpoint to detect, but a dynamic resolution function.
Hunting for credentials in build-process memory — not just on disk — expands the collection surface beyond repositories and configuration files. CI/CD tokens and short-lived OIDC keys, designed to reduce persistence, become targets during their active lifecycle.
IDE hooks and AI coding sessions as reactivation triggers introduce a vector tied to the development environment, not the operating system. Persistence no longer requires system modifications: opening a project in an integrated environment is enough.
Closing
The ChainDrop and PolinRider campaigns documented by Unit 42 do not represent a structural transformation of cybercrime, but a specific tactical evolution. The shift from static C2 endpoints to blockchain smart contracts is measurable, replicable, and — due to the characteristics of the underlying technology — particularly difficult to reverse with current tools. The source does not quantify the number of enterprise victims nor the volume of credentials actually exfiltrated. The report date, October 7, 2026, is not further contextualized.
Source: Unit 42, Palo Alto Networks — "Evolution of Web3 in Cloud Supply Chain Attacks" (October 7, 2026). URL: https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks/
Information is based on the cited source and current as of publication.
Sources
- https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks/
- https://unit42.paloaltonetworks.com/tools/
- https://unit42.paloaltonetworks.com/atoms/
- https://unit42.paloaltonetworks.com/about-unit-42/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.