# Web3 Cloud Supply Chain Attacks: ChainDrop & PolinRider Analysis

> Discover how threat actors use Web3 smart contracts for resilient command-and-control in enterprise cloud supply chain attacks.

- Published: 2026-10-08T03:37:55.000Z
- Severity: high
- Category: Supply Chain
- Tags: Supply Chain Attack, Web3, Cloud Security, Malware, NPM
- Author: Runtime Rebel Intel
- Primary source: https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks/
- Canonical: https://runtimerebel.com/blog/web3-cloud-supply-chain-attacks-chaindrop-polinrider-analysis

## Key points

- Threat actors are systematically adopting Web3 smart contracts for resilient command-and-control infrastructure during cloud supply chain compromises.
- Targeted environments include enterprise developer endpoints, continuous integration and continuous deployment pipelines, and public package registries like npm.
- Organizations must monitor for unexpected blockchain network traffic and enforce strict policy controls across all CI/CD runners.

## Overview of Web3 Command-and-Control in Cloud Supply Chain Attacks

Threat actors have systematically upgraded their command-and-control infrastructure by adopting decentralized blockchain web architectures, commonly referred to as Web3. According to the [2026 Unit 42 Global Incident Response Report](https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks/), software supply chain compromises have become a leading [initial access](/glossary#initial-access) vector targeting enterprise cloud environments. Instead of relying on static endpoints hardcoded into [malware](/glossary#malware) binaries, modern threat groups use Web3-powered smart contracts. This allows operators to dynamically update entire botnets and [worm](/glossary#worm) network infrastructures with a single smart contract transaction.

By poisoning open-source dependencies, malicious campaigns bypass traditional authentication perimeters. This operational shift enables threat actors to harvest sensitive data from developer endpoints and continuous integration and continuous deployment ([CI/CD](/glossary#ci-cd)) pipelines.

## Technical Analysis of ChainDrop and PolinRider

Recent supply chain campaigns illustrate how open-source packages are engineered to extract ephemeral cloud access keys and establish [persistence](/glossary#persistence) within developer workflows. State-sponsored groups, including North Korea-affiliated actors like Alluring Pisces, have operationalized these techniques across targets such as Axios, Mastra [AI](/glossary#ai), and Rust's arrayref.

### The ChainDrop Worm

Traced to the Shai-Hulud family, the ChainDrop campaign successfully infected over 400 npm packages, including widely used modules like keyv and cacheable-request. 

* **Execution Mechanism:** The worm executes a preinstall script hook that downloads a custom Bun runtime to launch an obfuscated credential harvester.
* **[Credential Harvesting](/glossary#credential-harvesting):** In addition to searching static disk files, the malware inspects memory inside running build processes to capture ephemeral cloud provider identity and access management ([IAM](/glossary#iam)) keys, CI/CD pipeline worker tokens, and short-lived OIDC federation keys.
* **Web3 [C2](/glossary#c2) Infrastructure:** To maintain long-term communication without relying on static domains, ChainDrop uses EtherHiding to query smart contract transactions. These transactions contain dynamically encrypted information for exfiltration endpoints.
* **Persistence:** The malware injects persistent task hooks, triggering automatic execution whenever a developer opens a project or starts an AI coding session.

### The PolinRider Campaign

Expanding across multiple package registries, including npm, Go modules, and Packagist, the PolinRider campaign conceals malicious loaders within repository configuration files, web resources, and developer IDE workspace automation. When a developer loads the workspace, the [payload](/glossary#payload) silently triggers to exfiltrate session tokens and environment secrets.

Rather than depending on standard methods, PolinRider variants dynamically resolve command-and-control endpoints using Web3 mechanisms. These mechanisms range from multi-chain transaction queries across networks like TRON, Aptos, and Binance Smart Chain to zero-data address resolution techniques like NullReceiver. By using a hybrid architecture with backup channels, attackers ensure their infrastructure survives traditional network monitoring and Web 2.0 takedowns.

## Considerations for Security Teams

Defending against decentralized command-and-control mechanisms requires targeted visibility and automated policy enforcement. Security teams should prioritize the following mitigations:

* **Evaluate Network Baseline Activity:** Determine whether your organization's business domain ever expects Web3 or blockchain network activity. If blockchain connectivity is unnecessary, block all associated outbound traffic.
* **Deploy Advanced [Endpoint](/glossary#endpoint) Protection:** Ensure endpoint and network security controls actively monitor and block processes attempting unauthorized communication with blockchain RPC gateways or multi-chain lookups.
* **Secure CI/CD Pipelines:** Implement strict automated policy controls across all version control systems and CI/CD runners to prevent unauthorized script execution during dependency resolution.

**Related:** [Jscrambler npm Package Backdoored with Infostealer Malware](/blog/jscrambler-npm-package-backdoored-with-infostealer-malware), [Jscrambler NPM Packages Poisoned in Supply Chain Attack](/blog/jscrambler-npm-packages-poisoned-in-supply-chain-attack)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/web3-cloud-supply-chain-attacks-chaindrop-polinrider-analysis
