Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Diagram of the ChainDrop npm worm attack flow from malicious package install through credential harvest and EtherHiding C2.
Figure: Unit 42, Figure 1, attack flow of the ChainDrop npm worm, Oct 7, 2026 (fair use).

Tools

Unit 42 Tracks ChainDrop and PolinRider Stealing Cloud Build Credentials Through Blockchain C2 Dead Drops

Unit 42 says supply chain worms are resolving command-and-control through EtherHiding, cross-chain transaction data, and NullReceiver address encoding so CI pipelines and developer hosts leak ephemeral cloud keys without hard-coded domains.

James Whitford, ToolsAustin6 min read

AUSTIN - Open-source supply chain malware is no longer just dropping hard-coded command-and-control domains into package hooks. Palo Alto Networks Unit 42 reported on Oct. 7 that recent campaigns, led by the ChainDrop npm worm and the PolinRider multi-registry campaign, resolve C2 through Web3 and blockchain mechanisms so operators can rotate infrastructure with a single transaction while harvesting ephemeral cloud credentials from developer workstations and CI/CD runners.

ChainDrop, which Unit 42 traces to the Shai-Hulud family, infected more than 400 npm packages, including widely used packages such as keyv and cacheable-request. Unit 42 said the worm runs a preinstall script that downloads a custom Bun runtime and launches an obfuscated credential harvester. Beyond scanning files on disk, the harvester searches memory inside running build processes for cloud IAM keys, CI/CD worker tokens, and short-lived OIDC federation keys, then terminates. To avoid static domains, ChainDrop uses EtherHiding: read-only JSON-RPC calls against smart contract state that store encrypted exfiltration endpoints, then injects persistent task hooks that fire when a developer opens a project or starts an AI coding session.

Unit 42 diagram showing ChainDrop preinstall execution, Bun runtime, memory credential theft, and blockchain C2 lookup.
Figure: Unit 42, Figure 1, ChainDrop npm worm attack flow, Oct 7, 2026 (fair use).ChainDrop reads C2 domains from an Ethereum contract, then plants editor hooks.

PolinRider expands the same cloud-theft goal across npm, Go modules, and Packagist. Instead of relying only on install scripts, Unit 42 said loaders hide in repository configuration files, web resources, and developer IDE workspace automation. When a workspace loads, the payload can exfiltrate developer credentials, cloud session tokens, and environment secrets while establishing persistence in enterprise build pipelines. Variants resolve C2 through multi-chain transaction queries on networks such as TRON, Aptos, and Binance Smart Chain, with zero-data address techniques such as NullReceiver as a fallback when primary RPC gateways are blocked.

Diagram of PolinRider loaders across package registries with multi-chain Web3 C2 resolution.
Figure: Unit 42, Figure 2, PolinRider multi-registry attack flow and Web3 C2 resolution, Oct 7, 2026 (fair use).PolinRider falls through TRON, Aptos, and BNB, then a zero-value Ethereum transfer.

Unit 42 frames that shift as three architectural phases. Phase 1 EtherHiding stores C2 domains in smart contract state and exposes the contract address in RPC payloads, giving defenders a static block point. Phase 2 TxDataHiding embeds encrypted C2 payloads in transaction calldata sent to router contracts or burn addresses, so operators can refresh endpoints by broadcasting a new transaction without changing state code. Phase 3 NullReceiver goes further: the loader reads an actor-controlled wallet's latest zero-value transaction, verifies an ASCII marker, and derives the active C2 IPv4 address from the recipient address itself, leaving no domain string or executable payload in the transaction for conventional filters to inspect.

Diagram showing NullReceiver extracting a C2 IPv4 address from a zero-value blockchain transaction recipient.
Figure: Unit 42, Figure 3, NullReceiver IPv4 address resolution extraction workflow, Oct 7, 2026 (fair use).The first four bytes of the recipient address become the C2 IPv4.

The cloud payoff is why SOC and platform teams should care. Unit 42 said stolen keys can open cloud management consoles and APIs and may bypass MFA when other controls are missing. The firm also ties related supply chain poisoning patterns to North Korea-affiliated activity tracked as Alluring Pisces (also known as Sapphire Sleet or Midnight Neptune), including campaigns against Axios, Mastra AI, and Rust's arrayref crate that sought cloud tokens and, in some cases, macOS code-signing certificates. Defensive guidance in the post is operational rather than product-only: decide whether any blockchain RPC traffic is ever expected in your estate; alert when non-crypto developer runtimes query public blockchain gateways; and automate policy checks on CI/CD runners and version control systems for unauthorized package lifecycle hooks, hidden scripts in manifests, and unverified workspace automation before build execution.

Sources:


James Whitford covers SOC tooling, SIEM, SOAR, and detection platforms for SOCtember from Austin.

Related stories

Tools desk