Published on October 8, 2026
Hackers Use Web3 and Blockchain C2 to Hide Supply Chain Attacks Targeting Cloud Credentials
Severity
Medium
Detail
Palo Alto Networks’ Unit 42 has published an analysis detailing a shift in software supply chain attacks, where threat actors are leveraging public blockchain networks as a decentralized command-and-control (C2) layer. Known as EtherHiding, this technique allows attackers to dynamically update data-exfiltration endpoints via smart contracts and public RPC nodes without modifying or republishing malicious code in developer environments.
The research highlights two major campaigns—ChainDrop, a self-propagating npm worm infecting over 400 packages, and PolinRider, a North Korea-aligned campaign targeting npm, Packagist, Go modules, and Chrome extensions. By embedding stealthy execution hooks inside local developer configurations and build runners, these operations harvest high-value cloud identity tokens, pipeline secrets, and source code credentials at scale.
How?
The infection process begins when a developer or automated build runner imports a compromised package containing a malicious lifecycle hook (such as an npm preinstall command). The script executes an obfuscated entry file (setup.mjs), which downloads and uses a legitimate JavaScript runtime, such as Bun, to execute its payload without relying on native system dependencies.
Once active on an endpoint or inside a CI/CD pipeline, the malware performs extensive credential harvesting. It inspects local files, environment variables, cloud metadata endpoints, and memory space associated with GitHub Actions runner processes. Through this inspection, the malware extracts short-lived OpenID Connect (OIDC) tokens, AWS/GCP cloud identity keys, SSH keys, Kubernetes tokens, Terraform state files, and Vault secrets.
To ensure long-term persistence, the malware writes stealthy execution hooks into local workspace configurations, adding automated VS Code tasks (.vscode/tasks.json) and AI coding assistant triggers (such as Claude Code SessionStart hooks) that execute the payload whenever a developer opens a project or starts a coding session.
To maintain C2 resilience and bypass traditional domain blocklists, the malware queries public blockchain RPC nodes or smart contracts at runtime to retrieve its active C2 server destination. During the ChainDrop campaign, the attackers updated an Ethereum smart contract in a single transaction to redirect data exfiltration from npm-cache[.]com to awqhnjewqjkl[.]icu, without needing to push updated packages to victims.
Similarly, the PolinRider campaign queried smart contracts across TRON, Aptos, and BNB Smart Chain to retrieve and execute encrypted second-stage payloads (such as DEV#POPPER and OmniStealer) hidden inside fake font files (.woff2) and configuration scripts (vite.config.js).
Conclusion
The integration of Web3 smart contracts into supply chain malware represents a significant evolution in C2 infrastructure resilience, rendering traditional domain-blocking strategies ineffective. Organizations must extend security visibility beyond package lockfiles into developer workspace configurations, editor settings, and network-level RPC queries.
To mitigate this threat, security teams should implement strict egress filtering on CI/CD runners and developer endpoints, blocking outbound Web3/RPC blockchain traffic unless explicitly required by business operations.
Organizations should enforce policies that restrict package lifecycle scripts (preinstall/postinstall) and monitor repository configuration files (such as .vscode/tasks.json and build configs) for unauthorized automation hooks. Additionally, enterprise security teams must enforce short-lived OIDC tokens for cloud access, isolate build environments, and immediately rotate all cloud keys, SSH credentials, and API secrets exposed on infected endpoints.
Source
