Hackers Use Web3 and Blockchain C2 to Hide Supply Chain Attacks Targeting Cloud Credentials
Unit 42 says the ChainDrop npm worm uses Ethereum smart contracts as C2 to steal cloud and developer credentials.
Unit 42 reported that the ChainDrop npm worm, which infected more than 400 packages, uses an Ethereum smart contract as a dead-drop to learn its data-theft server. A single transaction rotated command-and-control from npm-cache[.]com to awqhnjewqjkl[.]icu without republishing the malware. The worm harvests cloud credentials, npm and GitHub tokens, SSH keys, Kubernetes and Vault tokens, Terraform state, and short-lived GitHub Actions OIDC tokens, and it persists through VS Code tasks and a Claude Code hook. A related North Korea-aligned campaign, PolinRider, used TRON, Aptos, and BNB Smart Chain to fetch encrypted payloads such as DEV#POPPER and OmniStealer.