LIVE · cybersecurity feed
Live wire
breach

Evolution of Web3 in Cloud Supply Chain Attacks

Threat actors are increasingly leveraging Web3 technologies, including smart contracts and blockchain networks, to enhance their command-and-control (C2) infrastructure in cloud supply chain attacks. This evolution allows for dynamic updates to botnets and worm networks through single smart contract transactions, bypassing traditional Web 2.0-style network monitoring and making C2…

ZeroDay News ·

Source: Unit 42 (Palo Alto)

Threat actors are increasingly leveraging Web3 technologies, including smart contracts and blockchain networks, to enhance their command-and-control (C2) infrastructure in cloud supply chain attacks. This evolution allows for dynamic updates to botnets and worm networks through single smart contract transactions, bypassing traditional Web 2.0-style network monitoring and making C2 infrastructure more resilient to takedowns.

Software supply chain compromises have become a primary initial access vector for targeting enterprise cloud environments, according to the 2026 Unit 42 Global Incident Response Report. Attackers poison open-source dependencies to harvest elevated cloud identity tokens, service account keys, and deployment secrets from developer endpoints and continuous integration/continuous deployment (CI/CD) pipelines.

Recent campaigns, such as the ChainDrop npm worm and the PolinRider campaign, exemplify this shift. These operations are designed to extract ephemeral cloud access keys and establish persistence within developer workflows. North Korea-affiliated state-sponsored actors, including Alluring Pisces (also known as Sapphire Sleet or Midnight Neptune), have operationalized these techniques in campaigns targeting entities like Axios, Mastra AI, and Rust's arrayref.

Developer workstations and automated CI/CD runners represent a highly privileged attack surface, often holding sensitive Identity Access Management (IAM) keys or tokens. Current supply chain malware prioritizes extracting these credentials when software dependencies are resolved.

The ChainDrop npm worm, traced to the Shai-Hulud family, infected over 400 npm packages, including `keyv` and `cacheable-request`. It executes a preinstall script hook to download a custom Bun runtime, which then launches an obfuscated credential harvester. This harvester searches both static disk files and memory within running build processes to capture ephemeral cloud provider IAM keys, CI/CD pipeline worker tokens, and short-lived OIDC federation keys before terminating the runner. To maintain long-term communication without static domains, ChainDrop uses EtherHiding to query smart contract transactions, which contain dynamically encrypted information for exfiltration IP or domain endpoints. It then injects persistent task hooks for automatic execution when a developer opens a project or starts an AI coding session.

The PolinRider campaign spans multiple package registries, including npm, Go modules, and Packagist. Instead of relying solely on standard package installation scripts, PolinRider conceals malicious loaders within repository configuration files, web resources, and developer IDE workspace automation. When a developer loads the workspace, the payload silently triggers in the background to exfiltrate developer credentials, cloud session tokens, and environment secrets, while establishing long-term persistence within enterprise build pipelines. Different variants of the campaign dynamically resolve C2 endpoints using various Web3 mechanisms, from multi-chain transaction queries across networks like TRON, Aptos, and Binance Smart Chain (BSC) to zero-data address resolution techniques such as NullReceiver. To maximize reliability, threat actors deploy multiple mechanisms in a hybrid architecture, using zero-data transfers as a backup channel if primary remote procedure call (RPC) gateways or multi-chain lookups are blocked. Once extracted, these credentials can provide direct access to cloud management consoles and APIs, potentially bypassing multi-factor authentication (MFA) if other controls are not in place.

The architectural evolution of Web3 C2 has progressed through three distinct phases. Initially, in Phase 1, known as EtherHiding, early Web3 C2 implementations, reported in late 2024 npm supply chain campaigns, relied on deploying a hardcoded smart contract address on public blockchains. Malware loaders, like those in ChainDrop, issued read-only JSON-RPC calls (`eth_call`) to retrieve C2 domains stored in smart contract state variables. While this bypassed Web 2.0 DNS sinkholing, the fixed contract address created a single point of failure, as outbound JSON-RPC request payloads explicitly exposed the target contract address, allowing security controls to flag and block queries to that specific contract. DPRK-affiliated actors are reported to use EtherHiding for malware distribution and cryptocurrency theft.

Phase 2, known as Cross-Chain Transaction Data Hiding (TxDataHiding), emerged to overcome the single point of failure of hard-coded state contracts. Threat actors shifted from contract state storage to the transaction input data layer (calldata). Popularized in campaigns like PolinRider, this phase decouples C2 resolution from permanent smart contract getters. Instead of invoking state variables, operators embed encrypted C2 payloads within the transaction input data.

breachcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

US posts $10 million reward for accused Chinese ‘Hafnium’ hacker

The U.S. State Department has announced a reward of up to $10 million for information leading to the arrest or conviction of Zhang Yu, a Chinese national accused of involvement in the Hafnium hacking campaign. Zhang is alleged to be a central figure in a series of cyberattacks that compromised thousands of computers globally and stole sensitive data, including COVID-19 research.

breach

Major rules for federal contractors handling sensitive data are nearing the finish line

Federal government contractors handling sensitive information are poised for significant new regulations concerning data protection and breach reporting. These forthcoming rules, which define "controlled unclassified information" (CUI) as a category of sensitive data below classified status—including personal information like Social Security numbers and critical infrastructure…

ransomware

Smashing Security podcast #487: Clippy’s crypto comeback

Microsoft's official Twitter account, which boasts 13 million followers, was reportedly compromised by an attacker who used the platform to promote a cryptocurrency scam. The incident, which occurred on October 8, 2026, involved the attacker posting an image of Clippy, Microsoft's former animated assistant, alongside a promotion for a "dodgy crypto coin."

ransomware

Ransomware recovery CEO charged over secret ransom payments

The owner of MonsterCloud, a ransomware remediation company, has been charged with allegedly defrauding clients by secretly paying ransoms to cybercriminals while claiming to use proprietary technology for data recovery. Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23, 2026, and arraigned…

security

Cisco quantum network controller lets apps order entanglement on demand

Cisco has unveiled a Quantum Network Controller, a research prototype designed to enable applications to request entanglement on demand from a quantum network, abstracting away the underlying hardware complexities. This controller manages the distribution of entanglement, a linked quantum state shared between distant points, which is a critical resource for quantum networks.

ai

Australian Gov't Weighs Mandatory AI Incident Reporting

The Australian government is reportedly considering the implementation of mandatory incident reporting requirements for companies developing and deploying frontier artificial intelligence systems. This move comes after an incident involving an "agentic attack" against the nation's Medicare systems, prompting a re-evaluation of regulatory frameworks for advanced AI.