Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Hackers Hide C2 on Blockchain via Negative Hotel Review Malware
October 8, 2026
Critical Sungrow Inverter Vulnerability Lets Attackers Access Solar Plants
October 8, 2026
Critical LMCache Flaw (CVE-2024-XXXX) Gets PoC, Enables RCE
October 8, 2026
Home/CyberSecurity News/Web3 Blockchain C2 Conceals Supply Chain Attacks on Cloud Credentials
CyberSecurity News

Web3 Blockchain C2 Conceals Supply Chain Attacks on Cloud Credentials

Key Takeaways Threat actors are increasingly leveraging public blockchain networks as a resilient command-and-control (C2) infrastructure for supply chain malware. This method allows attackers to...

David kimber
David kimber
October 8, 2026 5 Min Read
2 0

Key Takeaways

  • Threat actors are increasingly leveraging public blockchain networks as a resilient command-and-control (C2) infrastructure for supply chain malware.
  • This method allows attackers to dynamically update C2 servers without altering malicious code on infected systems, bypassing traditional domain blocklists.
  • The ChainDrop npm worm, a self-propagating malware, infected over 400 packages and was observed exfiltrating a wide array of sensitive cloud and development credentials.
  • Another campaign, PolinRider, demonstrates the expansion of this technique beyond npm, utilizing various package managers and public RPC services to deliver encrypted payloads.
  • Organizations, especially those with cloud-focused operations, face heightened risk as compromised open-source packages can steal temporary cloud identity tokens and other critical data from developer environments and CI/CD pipelines.

Blockchain C2: A New Frontier for Supply Chain Attacks

Cybersecurity researchers are observing a significant shift in attacker tactics, with malicious actors now employing public blockchain networks to establish command-and-control (C2) channels for software supply chain malware. This innovative approach grants attackers a robust mechanism to update their infrastructure without needing to modify the malicious code already deployed on compromised developer systems. The implications are particularly severe for organizations heavily reliant on cloud environments.

Table Of Content

  • Key Takeaways
  • Blockchain C2: A New Frontier for Supply Chain Attacks
  • ChainDrop: A Case Study in Blockchain-Enabled Credential Theft
  • Hackers Leverage Web3 and Blockchain for C2 Evasion
  • ChainDrop’s Attack on Development Workflows
  • PolinRider: Expanding the Blockchain C2 Threat
  • What You Should Do
  • Indicators of Compromise (IoCs)

This method provides a resilient pathway for criminals to redirect infected software packages to new data exfiltration servers, thereby diminishing the effectiveness of conventional domain blocklisting strategies. The danger is amplified for cloud-centric organizations, as tainted open-source packages can execute within developer workstations and CI/CD pipelines. From these vantage points, they can access highly sensitive data, including temporary cloud identity tokens, deployment secrets, service-account keys, and GitHub credentials.

ChainDrop: A Case Study in Blockchain-Enabled Credential Theft

A recent investigation into the ChainDrop npm worm highlighted how trusted publishing channels can be exploited. Ordinary dependency updates and project configurations were weaponized to facilitate credential theft. Analysts at Unit 42 identified ChainDrop as a self-propagating npm worm that infiltrated more than 400 packages.

The research revealed that ChainDrop systematically harvested a broad spectrum of credentials, including cloud credentials, npm and GitHub tokens, SSH keys, Kubernetes tokens, Terraform state files, and Vault tokens, along with other secrets present in developer environments. Furthermore, the malware was designed to scan the memory of GitHub Actions runner processes for ephemeral OpenID Connect (OIDC) tokens and runner secrets.

Hackers Leverage Web3 and Blockchain for C2 Evasion

Traditionally, malware operations involve hard-coding a specific domain or IP address into the malicious code for C2 communication. This practice offers a clear target for defense, allowing security teams to block the address, registrars to suspend the domain, and package platforms to scan for known indicators. Blockchain C2 fundamentally alters this paradigm.

Instead of a static C2 address, the malware queries a smart contract or blockchain transaction during runtime to retrieve its current destination. ChainDrop exemplified this technique by utilizing an Ethereum smart contract. Unit 42 reported that the worm queried this contract to obtain the data exfiltration address, subsequently shifting its C2 from npm-cache[.]com to awqhnjewqjkl[.]icu via a single Ethereum transaction. This C2 rotation required no re-publishing of packages or distribution of new malware versions to victims, a technique commonly known as EtherHiding.

It is crucial to understand that the blockchain itself is not inherently malicious. Rather, its public and decentralized architecture is being misused by criminals as a dynamic address book, a repository for payloads, or a dead-drop service. Previous reports on EtherHiding malware delivery have detailed how smart contracts can return encoded JavaScript payloads, empowering operators to modify delivery content without altering compromised websites.

ChainDrop’s Attack on Development Workflows

The ChainDrop infection typically initiates through a modified npm package containing a preinstall command. This command triggers setup.mjs, which downloads the legitimate Bun JavaScript runtime if not already present, then uses it to execute an obfuscated payload. It’s important to note that the Bun runtime itself was not compromised; attackers merely leveraged it for code execution.

Once activated, the malware scans local files, environment variables, and cloud metadata services for credentials. It also targets active build processes, a critical detail given that CI/CD systems frequently employ temporary credentials that are not persistently stored on disk. While valid, these temporary tokens can provide attackers with direct access to cloud APIs, deployment environments, or source-code systems.

ChainDrop also established persistence within developer toolchains. It achieved this by writing a VS Code task designed to execute upon folder opening and by adding a Claude Code SessionStart hook. This means a developer could inadvertently trigger the malware simply by opening a project or initiating an AI coding session. This vulnerability mirrors the broader ChainDrop campaign’s exposure of developer tool configurations, where trusted local project files became an execution vector.

PolinRider: Expanding the Blockchain C2 Threat

A separate campaign, dubbed PolinRider, indicates that this blockchain C2 model is expanding beyond the npm ecosystem. Researchers have linked PolinRider to North Korea-aligned threat activity, uncovering malicious loaders in npm, Packagist, Go modules, and Chrome extensions. These loaders employed blockchain technology and public RPC services connected to TRON, Aptos, and BNB Smart Chain to retrieve encrypted follow-on payloads.

The campaign ingeniously concealed its code within files that appear innocuous to many developers, such as vite.config.js, fake .woff2 font files, and .vscode/tasks.json. This tactic is effective because many dependency scanning tools primarily focus on package manifests and lockfiles, often overlooking editor settings, workspace automation, or repository configurations. The earlier hidden JavaScript loader campaign also demonstrated how PolinRider utilized such files to deliver DEV#POPPER and OmniStealer payloads.

What You Should Do

  • Organizations should scrutinize blockchain traffic originating from build runners and developer endpoints, especially if there is no legitimate Web3 business requirement.
  • Regularly review package lifecycle scripts and thoroughly inspect repository configuration files for anomalies.
  • Implement strict isolation for CI/CD runners to limit the blast radius of potential compromises.
  • Restrict outbound network connections from build systems to only essential services.
  • Immediately rotate all credentials accessible from any host identified as affected by these campaigns.

Indicators of Compromise (IoCs)

IoC Type Indicator Detection Context
Ethereum smart contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103 ChainDrop C2 resolver contract queried through Ethereum RPC services
Ethereum transaction 0xc55920f1bd0531b6738153068a666c080ddded47e6256f1fd980d51c0b507c91 Transaction used to rotate the ChainDrop C2 domain
Ethereum wallet 0x55F9780ef31cD Wallet reported as the deployer of the C2 resolver contract
C2 domain npm-cache[.]com Earlier active ChainDrop exfiltration endpoint
C2 domain pypi-get[.]com Domain stored in the original resolver contract list
C2 domain js-mirror[.]com Domain stored in the original resolver contract list
C2 domain awqhnjewqjkl[.]icu Rotated ChainDrop C2 domain observed after the Ethereum transaction
File artifact .claude/math_init.js Obfuscated ChainDrop JavaScript payload
File artifact .claude/settings.json Claude Code SessionStart persistence configuration
File artifact .claude/setup.mjs Dropper copy used in persistence chain
File artifact .vscode/setup.mjs Dropper copy linked to VS Code persistence
File artifact .vscode/tasks.json VS Code task configured to run when a project folder opens
File artifact .github/workflows/codeql_analysis.yml Malicious workflow template used to serialize GitHub secrets
String marker thebeautifulmarchoftime GitHub commit-history fallback marker for C2 resolution
String marker IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients Marker used in commit messages containing stolen tokens

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

VirusTotal API Keys Allegedly Sold on Dark Web

Next Post

FBI and Ghana Police Bust Cybercrime Ring, Seize 300+ Devices

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Web3 Blockchain C2 Conceals Supply Chain Attacks on Cloud Credentials
October 8, 2026
VirusTotal API Keys Allegedly Sold on Dark Web
October 8, 2026
Critical Zammad RCE Flaw CVE-2023-44606 Gets Proof-of-Concept Exploit
October 8, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us