Overview of Web3 Command-and-Control in Cloud Supply Chain Attacks
Threat actors have systematically upgraded their command-and-control infrastructure by adopting decentralized blockchain web architectures, commonly referred to as Web3. According to the 2026 Unit 42 Global Incident Response Report, software supply chain compromises have become a leading initial access vector targeting enterprise cloud environments. Instead of relying on static endpoints hardcoded into malware binaries, modern threat groups use Web3-powered smart contracts. This allows operators to dynamically update entire botnets and worm network infrastructures with a single smart contract transaction.
By poisoning open-source dependencies, malicious campaigns bypass traditional authentication perimeters. This operational shift enables threat actors to harvest sensitive data from developer endpoints and continuous integration and continuous deployment (CI/CD) pipelines.
Technical Analysis of ChainDrop and PolinRider
Recent supply chain campaigns illustrate how open-source packages are engineered to extract ephemeral cloud access keys and establish persistence within developer workflows. State-sponsored groups, including North Korea-affiliated actors like Alluring Pisces, have operationalized these techniques across targets such as Axios, Mastra AI, and Rust’s arrayref.
The ChainDrop Worm
Traced to the Shai-Hulud family, the ChainDrop campaign successfully infected over 400 npm packages, including widely used modules like keyv and cacheable-request.
- Execution Mechanism: The worm executes a preinstall script hook that downloads a custom Bun runtime to launch an obfuscated credential harvester.
- Credential Harvesting: In addition to searching static disk files, the malware inspects memory inside running build processes to capture ephemeral cloud provider identity and access management (IAM) keys, CI/CD pipeline worker tokens, and short-lived OIDC federation keys.
- Web3 C2 Infrastructure: To maintain long-term communication without relying on static domains, ChainDrop uses EtherHiding to query smart contract transactions. These transactions contain dynamically encrypted information for exfiltration endpoints.
- Persistence: The malware injects persistent task hooks, triggering automatic execution whenever a developer opens a project or starts an AI coding session.
The PolinRider Campaign
Expanding across multiple package registries, including npm, Go modules, and Packagist, the PolinRider campaign conceals malicious loaders within repository configuration files, web resources, and developer IDE workspace automation. When a developer loads the workspace, the payload silently triggers to exfiltrate session tokens and environment secrets.
Rather than depending on standard methods, PolinRider variants dynamically resolve command-and-control endpoints using Web3 mechanisms. These mechanisms range from multi-chain transaction queries across networks like TRON, Aptos, and Binance Smart Chain to zero-data address resolution techniques like NullReceiver. By using a hybrid architecture with backup channels, attackers ensure their infrastructure survives traditional network monitoring and Web 2.0 takedowns.
Considerations for Security Teams
Defending against decentralized command-and-control mechanisms requires targeted visibility and automated policy enforcement. Security teams should prioritize the following mitigations:
- Evaluate Network Baseline Activity: Determine whether your organization’s business domain ever expects Web3 or blockchain network activity. If blockchain connectivity is unnecessary, block all associated outbound traffic.
- Deploy Advanced Endpoint Protection: Ensure endpoint and network security controls actively monitor and block processes attempting unauthorized communication with blockchain RPC gateways or multi-chain lookups.
- Secure CI/CD Pipelines: Implement strict automated policy controls across all version control systems and CI/CD runners to prevent unauthorized script execution during dependency resolution.
Related: Jscrambler npm Package Backdoored with Infostealer Malware, Jscrambler NPM Packages Poisoned in Supply Chain Attack