
Unit 42 Tracks ChainDrop and PolinRider Stealing Cloud Build Credentials Through Blockchain C2 Dead Drops
Unit 42 says supply chain worms are resolving command-and-control through EtherHiding, cross-chain transaction data, and NullReceiver address encoding so CI pipelines and developer hosts leak ephemeral cloud keys without hard-coded domains.
James Whitford, ToolsAustin6 min read
AUSTIN - Open-source supply chain malware is no longer just dropping hard-coded command-and-control domains into package hooks. Palo Alto Networks Unit 42 reported on Oct. 7 that recent campaigns, led by the ChainDrop npm worm and the PolinRider multi-registry campaign, resolve C2 through Web3 and blockchain mechanisms so operators can rotate infrastructure with a single transaction while harvesting ephemeral cloud credentials from developer workstations and CI/CD runners.
ChainDrop, which Unit 42 traces to the Shai-Hulud family, infected more than 400 npm packages, including widely used packages such as keyv and cacheable-request. Unit 42 said the worm runs a preinstall script that downloads a custom Bun runtime and launches an obfuscated credential harvester. Beyond scanning files on disk, the harvester searches memory inside running build processes for cloud IAM keys, CI/CD worker tokens, and short-lived OIDC federation keys, then terminates. To avoid static domains, ChainDrop uses EtherHiding: read-only JSON-RPC calls against smart contract state that store encrypted exfiltration endpoints, then injects persistent task hooks that fire when a developer opens a project or starts an AI coding session.

PolinRider expands the same cloud-theft goal across npm, Go modules, and Packagist. Instead of relying only on install scripts, Unit 42 said loaders hide in repository configuration files, web resources, and developer IDE workspace automation. When a workspace loads, the payload can exfiltrate developer credentials, cloud session tokens, and environment secrets while establishing persistence in enterprise build pipelines. Variants resolve C2 through multi-chain transaction queries on networks such as TRON, Aptos, and Binance Smart Chain, with zero-data address techniques such as NullReceiver as a fallback when primary RPC gateways are blocked.

Unit 42 frames that shift as three architectural phases. Phase 1 EtherHiding stores C2 domains in smart contract state and exposes the contract address in RPC payloads, giving defenders a static block point. Phase 2 TxDataHiding embeds encrypted C2 payloads in transaction calldata sent to router contracts or burn addresses, so operators can refresh endpoints by broadcasting a new transaction without changing state code. Phase 3 NullReceiver goes further: the loader reads an actor-controlled wallet's latest zero-value transaction, verifies an ASCII marker, and derives the active C2 IPv4 address from the recipient address itself, leaving no domain string or executable payload in the transaction for conventional filters to inspect.

The cloud payoff is why SOC and platform teams should care. Unit 42 said stolen keys can open cloud management consoles and APIs and may bypass MFA when other controls are missing. The firm also ties related supply chain poisoning patterns to North Korea-affiliated activity tracked as Alluring Pisces (also known as Sapphire Sleet or Midnight Neptune), including campaigns against Axios, Mastra AI, and Rust's arrayref crate that sought cloud tokens and, in some cases, macOS code-signing certificates. Defensive guidance in the post is operational rather than product-only: decide whether any blockchain RPC traffic is ever expected in your estate; alert when non-crypto developer runtimes query public blockchain gateways; and automate policy checks on CI/CD runners and version control systems for unauthorized package lifecycle hooks, hidden scripts in manifests, and unverified workspace automation before build execution.
Sources:
James Whitford covers SOC tooling, SIEM, SOAR, and detection platforms for SOCtember from Austin.
Related stories
Response
Poisoned Tensorlake npm Release Hid a Worm That Deletes Home Directories if Victims Revoke the Stolen Token
Threat Intel
Iran-Linked Hackers Posing as Dubai Airports Recruiters Hide Malware in a Visual Studio Coding Test
Detection
Attackers Are Testing Stolen AWS Keys for Amazon Bedrock Access, Leaving a Pattern Defenders Can Spot
Detection