Skip to main content
Emerging ThreatsSupply Chain Attacks

Web3 Enables Sophisticated Cloud Supply Chain Attacks

Cluttered developer workstation with laptop, papers, and empty coffee cups, symbolizing a supply chain attack in a cloud…

ChainDrop infected over 400 npm packages by using a preinstall hook that downloads a custom runtime and launches an obfuscated credential harvester, according to Unit 42’s reporting — a startling illustration of how malware authors now weaponize blockchain primitives to run resilient command-and-control (C2) for cloud-focused supply chain attacks.

ChainDrop and the shift to smart-contract C2

Unit 42 traces ChainDrop to the Shai‑Hulud family. The worm propagated through more than 400 npm packages — including keyv and cacheable-request — by abusing a preinstall script hook to drop a custom Bun runtime and execute an obfuscated credential harvester. The loader searches both disk and memory inside running build processes to capture ephemeral cloud provider IAM keys, CI/CD pipeline worker tokens, and short‑lived OIDC federation keys before terminating the runner.

To avoid static, takedown‑prone infrastructure, ChainDrop uses what the report calls EtherHiding: the loader issues read‑only JSON‑RPC calls (eth_call) to smart contract state to retrieve encrypted C2 endpoints. Embedding C2 in contract state sidesteps DNS sinkholing and IP blocklisting, but static contract addresses can be flagged because outbound JSON‑RPC payloads explicitly expose the target contract address.

PolinRider, NullReceiver, and cross‑chain fallback

PolinRider — attributed to DPRK‑affiliated actors in multiple vendor briefings cited by Unit 42 — broadened the technique across registries (npm, Go modules, Packagist) and delivery vectors (repo configuration files, web resources, IDE workspace automation). PolinRider variants conceal loaders in workspace automation so the payload triggers silently when a developer loads a project, exfiltrating credentials and establishing persistence in build pipelines.

Operators evolved beyond EtherHiding. Under the TxDataHiding taxonomy, actors embed encrypted C2 payloads in transaction input data (calldata) and parse historical transactions (for example via eth_getTransactionByHash) to decode active payloads. PolinRider implementations use multi‑tier fallback routes across networks such as TRON, Aptos and Binance Smart Chain (BSC); if one chain or router is flagged, the actor broadcasts a fresh transaction on another chain to update C2 endpoints without changing on‑chain state.

NullReceiver represents a further minimization: loaders query an actor‑controlled wallet’s latest zero‑value transaction and mathematically extract an active C2 IPv4 address from the 20‑byte recipient address itself. With zero value and zero data, there is no contract, calldata, or domain string for security filters to inspect.

Why cloud environments and developer endpoints are the prize

Unit 42 and other vendors’ telemetry show supply chain compromises are a leading initial access vector into enterprise cloud environments. By poisoning open‑source dependencies, attackers bypass perimeter controls and harvest elevated cloud identity tokens, service account keys, deployment secrets, and macOS code‑signing certificates. The report cites three concrete supply chain operations as examples: the Axios compromise (a backdoored axios dependency named plain‑crypto‑js), Mastra AI poisoned npm packages targeting AI workflows, and a poisoned Rust arrayref crate on crates.io that executed a second‑stage payload during native compilation.

Once extracted, these credentials can provide direct access to cloud management consoles and management APIs and may bypass multi‑factor authentication if compensating controls are not present.

Considerations for security teams

  • Determine whether Web3 or blockchain network activity is expected. For organizations with no legitimate Web3 operations, any outbound blockchain interaction is a high‑confidence anomaly, and the report calls this an “easy win.”
  • Configure endpoint protection and network security for deep process‑level inspection across developer workstations and CI/CD runners. Monitor runtimes, scripting engines and compiler binaries, and alert when non‑crypto development tools initiate outbound JSON‑RPC or gateway queries.
  • Automate policy controls across CI/CD runners and version control systems to flag unauthorized changes to repository configuration files, hidden script injections in package manifests, and unverified package lifecycle hooks before build execution.
  • Move from reactive IoC matching to proactive behavioral visibility, using analytics to baseline developer traffic and detect subtle on‑chain evasion techniques such as multi‑chain lookups or zero‑data transactions.

What this means for open‑source maintainers, enterprise technologists, and procurement leaders

Open‑source maintainers must be aware that a compromised maintainer account or registry scope can convert a single package into a wide‑impact initial access vector; Unit 42 documents how one maintainer compromise spread to enterprise build pipelines. Enterprise technologists and security teams should prioritize hardening developer workstations and CI/CD runners where ephemeral credentials are exposed, and automate pre‑build policy checks. Procurement leaders and cloud owners should treat the presence of elevated service account keys in build artifacts as a high‑risk finding and require stronger controls around secret management in developer workflows.

Decentralized C2 techniques — EtherHiding, TxDataHiding, NullReceiver — are not hypothetical. They are documented, weaponized, and tailored to survive Web 2.0 takedowns by blending malicious lookups into routine developer traffic. The practical response Unit 42 prescribes is deliberate: deny unnecessary blockchain access, inspect processes and build runners, and automate policy across CI/CD and version control systems. If defenders follow that prescription, an “easy win” exists for organizations that do not legitimately use Web3; if they do not, the next supply chain compromise may replace a single takedownable domain with a chain of near‑unstoppable transactions.

Original report — Unit 42: Evolution of Web3 in Cloud Supply Chain Attacks