Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Threat actors have systematically upgraded their command-and-control infrastructure to leverage Web3 and blockchain smart contracts. The discovery, published by Palo Alto Networks Unit 42, documents two campaigns — ChainDrop and PolinRider — that exploit open-source supply-chain compromise as an initial access vector into enterprise cloud environments.
The stakes are architectural: traditional security controls based on blocking static domains and IP addresses lose effectiveness against decentralized C2 that can be updated with a single transaction.
- The ChainDrop campaign infected over 400 npm packages, including keyv and cacheable-request, using a worm with a preinstall script hook
- ChainDrop employs the EtherHiding technique to query Ethereum smart contracts and dynamically retrieve encrypted exfiltration endpoints
- PolinRider extends the attack to npm, Go modules, and Packagist, with C2 resolution on TRON, Aptos, and Binance Smart Chain
- According to the 2026 Unit 42 Global Incident Response Report, 65% of initial access techniques are identity-based
From Hardcoded Domains to Smart Contracts: ChainDrop's EtherHiding Architecture
ChainDrop, attributed to the Shai-Hulud family, represents the evolution of supply-chain malware toward the enterprise cloud. The worm infected over 400 npm packages, including the notable packages keyv and cacheable-request, injecting preinstallation scripts that activate during dependency installation.
The C2 mechanism rests on EtherHiding. Threat actors publish transactions on Ethereum smart contracts containing dynamically encrypted information; when queried by loaders in the compromised packages, these transactions return the current exfiltration endpoints — IP addresses or domains.
The immutable yet updatable nature of the blockchain ensures that a single transaction can redefine the entire botnet infrastructure, rendering blocks based on static threat intelligence ineffective.
Persistence is equally aggressive. ChainDrop injects persistent task hooks that trigger when a developer opens a project or starts an AI coding session. The search for cloud IAM credentials, CI/CD tokens, and ephemeral OIDC keys occurs both on disk and in the memory of running build processes.
Extracted credentials can provide direct access to cloud management consoles and APIs, bypassing MFA where other controls are absent.
"Threat actors have systematically upgraded their command-and-control (C2) infrastructure to use Web3, also known as Web 3.0 or decentralized blockchain web architectures" — Unit 42/Palo Alto Networks
PolinRider and Multi-Chain Logic: TRON, Aptos, and Zero-Data Resolution
The PolinRider campaign expands the scope beyond npm to Go modules and Packagist. Loaders are hidden in repository configuration files, web resources, and IDE workspace automations, increasing the infection surface beyond the JavaScript ecosystem alone.
PolinRider's C2 architecture stands out for its use of multi-chain Web3 mechanisms. Loaders dynamically resolve C2 endpoints through transaction queries on networks such as TRON, Aptos, and Binance Smart Chain. The NullReceiver technique, named but not technically detailed in the source, falls under the category of zero-data address resolution.
Threat actors deploy hybrid architectures with multiple Web3 techniques to maximize C2 reliability, using zero-data transfers as a backup channel in case primary RPC gateways or multi-chain queries are blocked.
65% of Initial Access Is Identity-Based: The Unit 42 Report Context
The 2026 Unit 42 Global Incident Response Report places software supply-chain compromises among the leading initial access vectors for enterprise cloud environments. The report contextualizes this with a striking figure: 65% of initial access techniques are identity-based.
This confirms that the ultimate goal of supply-chain loaders is the theft of credentials and tokens, not mere defacement or cryptojacking. Compromised open-source packages do not target generic user endpoints but developer workstations and CI/CD runners — high-privilege surfaces with access to deployment pipelines and production cloud environments.
The extraction of ephemeral OIDC tokens is particularly relevant because these tokens, though temporary, can have sufficient lifetime to establish lateral sessions in target cloud services.
What to Do Now
The Unit 42 dossier documents a paradigm shift with concrete implications for organizations managing enterprise cloud environments. Three elements demand immediate attention.
First: inspect traffic to blockchain endpoints. Enterprise controls oriented to DNS, HTTP/S, and standard-port communications do not detect C2 communications to RPC gateways and validator nodes. Smart contract queries on Ethereum, TRON, Aptos, and Binance Smart Chain traverse corporate networks without specific inspection in traditional deployments.
Second: verify the provenance of the 400+ compromised npm packages, including keyv and cacheable-request. The chain of trust breaks upstream of any runtime scan: malicious code enters through transitive dependencies before post-installation security tools can intervene.
Third: monitor build processes for memory accesses involving CI/CD tokens and ephemeral OIDC keys. The 65% identity-based initial access techniques documented by Unit 42 indicate that compromise of these credentials is the end goal of the ChainDrop and PolinRider campaigns, not a side effect.
Implications for Cloud Security
The shift from hardcoded domains to blockchain smart contracts as C2 backbone represents a qualitatively different challenge for security teams. Web3 infrastructures do not depend on renewable DNS registrations or compromisable hosting: once the smart contract is deployed, the C2 persists on the blockchain until specific interventions on the control wallets.
The hybrid architectures documented by Unit 42 — with EtherHiding on Ethereum, multi-chain queries on TRON, Aptos, and Binance Smart Chain, and zero-data transfers as backup — confirm that threat actors are investing in operational resilience, not proof-of-concept.
For organizations, the attack vector remains the open-source supply chain. ChainDrop's 400+ npm packages and PolinRider's extension to Go modules and Packagist demonstrate that no package manager ecosystem is exempt from risk.
The 65% identity-based techniques figure from the 2026 Unit 42 Global Incident Response Report provides the benchmark metric: supply-chain defense has become cloud identity defense, and static network controls no longer suffice.
Information is based on the cited source and current as of publication.
Sources
- https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks/
- https://unit42.paloaltonetworks.com/tools/
- https://unit42.paloaltonetworks.com/atoms/
- https://unit42.paloaltonetworks.com/about-unit-42/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.