Threat actors are increasingly leveraging Web3 technologies, including smart contracts and blockchain networks, to enhance their command-and-control (C2) infrastructure in cloud supply chain attacks. This evolution allows for dynamic updates to botnets and worm networks through single smart contract transactions, bypassing traditional Web 2.0-style network monitoring and making C2 infrastructure more resilient to takedowns.
Software supply chain compromises have become a primary initial access vector for targeting enterprise cloud environments, according to the 2026 Unit 42 Global Incident Response Report. Attackers poison open-source dependencies to harvest elevated cloud identity tokens, service account keys, and deployment secrets from developer endpoints and continuous integration/continuous deployment (CI/CD) pipelines.
Recent campaigns, such as the ChainDrop npm worm and the PolinRider campaign, exemplify this shift. These operations are designed to extract ephemeral cloud access keys and establish persistence within developer workflows. North Korea-affiliated state-sponsored actors, including Alluring Pisces (also known as Sapphire Sleet or Midnight Neptune), have operationalized these techniques in campaigns targeting entities like Axios, Mastra AI, and Rust's arrayref.
Developer workstations and automated CI/CD runners represent a highly privileged attack surface, often holding sensitive Identity Access Management (IAM) keys or tokens. Current supply chain malware prioritizes extracting these credentials when software dependencies are resolved.
The ChainDrop npm worm, traced to the Shai-Hulud family, infected over 400 npm packages, including `keyv` and `cacheable-request`. It executes a preinstall script hook to download a custom Bun runtime, which then launches an obfuscated credential harvester. This harvester searches both static disk files and memory within running build processes to capture ephemeral cloud provider IAM keys, CI/CD pipeline worker tokens, and short-lived OIDC federation keys before terminating the runner. To maintain long-term communication without static domains, ChainDrop uses EtherHiding to query smart contract transactions, which contain dynamically encrypted information for exfiltration IP or domain endpoints. It then injects persistent task hooks for automatic execution when a developer opens a project or starts an AI coding session.
The PolinRider campaign spans multiple package registries, including npm, Go modules, and Packagist. Instead of relying solely on standard package installation scripts, PolinRider conceals malicious loaders within repository configuration files, web resources, and developer IDE workspace automation. When a developer loads the workspace, the payload silently triggers in the background to exfiltrate developer credentials, cloud session tokens, and environment secrets, while establishing long-term persistence within enterprise build pipelines. Different variants of the campaign dynamically resolve C2 endpoints using various Web3 mechanisms, from multi-chain transaction queries across networks like TRON, Aptos, and Binance Smart Chain (BSC) to zero-data address resolution techniques such as NullReceiver. To maximize reliability, threat actors deploy multiple mechanisms in a hybrid architecture, using zero-data transfers as a backup channel if primary remote procedure call (RPC) gateways or multi-chain lookups are blocked. Once extracted, these credentials can provide direct access to cloud management consoles and APIs, potentially bypassing multi-factor authentication (MFA) if other controls are not in place.
The architectural evolution of Web3 C2 has progressed through three distinct phases. Initially, in Phase 1, known as EtherHiding, early Web3 C2 implementations, reported in late 2024 npm supply chain campaigns, relied on deploying a hardcoded smart contract address on public blockchains. Malware loaders, like those in ChainDrop, issued read-only JSON-RPC calls (`eth_call`) to retrieve C2 domains stored in smart contract state variables. While this bypassed Web 2.0 DNS sinkholing, the fixed contract address created a single point of failure, as outbound JSON-RPC request payloads explicitly exposed the target contract address, allowing security controls to flag and block queries to that specific contract. DPRK-affiliated actors are reported to use EtherHiding for malware distribution and cryptocurrency theft.
Phase 2, known as Cross-Chain Transaction Data Hiding (TxDataHiding), emerged to overcome the single point of failure of hard-coded state contracts. Threat actors shifted from contract state storage to the transaction input data layer (calldata). Popularized in campaigns like PolinRider, this phase decouples C2 resolution from permanent smart contract getters. Instead of invoking state variables, operators embed encrypted C2 payloads within the transaction input data.






