ChainDrop and PolinRider Use Blockchain C2 to Steal Cloud and CI/CD Credentials
ChainDrop and North Korea-linked PolinRider use blockchain C2 to steal cloud and CI/CD credentials.
Unit 42 reports that the ChainDrop npm worm and DPRK-linked PolinRider loader resolve command-and-control through blockchain data, letting operators redirect victims with an on-chain update. ChainDrop, tied to the Shai-Hulud lineage, infected more than 400 npm packages, including keyv and cacheable-request, and searches GitHub Actions Runner.Worker memory for short-lived OIDC tokens as well as npm, GitHub, SSH, Kubernetes, Terraform, and Vault secrets. It persists via VS Code tasks and Claude Code hooks and can republish itself with stolen npm tokens. Socket linked PolinRider to 162 malicious artifacts across 108 packages on npm, Go, Packagist, and Chrome; it uses TRON, Aptos, and BNB Smart Chain and drops DEV#POPPER and OmniStealer.
- ChainDrop infected over 400 npm packages, including keyv and cacheable-request.
- It harvests OIDC tokens from GitHub Actions runner memory plus cloud secrets.
- EtherHiding queries an Ethereum contract so operators can rotate exfiltration domains.
- PolinRider covered 162 artifacts in 108 packages and is linked to Famous Chollima.
- DEV#POPPER and OmniStealer steal credentials and wallets and run remote commands.
Full article781 words · extracted from gbhackers.com · click to collapse
Threat actors are increasingly using blockchain networks as resilient command-and-control infrastructure to steal cloud credentials from developer endpoints and CI/CD environments.
Recent campaigns involving the ChainDrop npm worm and the North Korea-linked PolinRider operation show how poisoned open-source packages can harvest short-lived cloud tokens, service-account credentials, deployment secrets, and source-code access tokens while resolving attacker infrastructure through Web3 services.
The shift matters because blockchain-backed C2 removes the static domains and IP addresses defenders traditionally block.
Rather than embedding a fixed server address in malware, attackers can retrieve encrypted C2 details from smart-contract state, blockchain transaction data or even zero-value wallet transfers.
An operator can then redirect compromised hosts to new infrastructure through a single on-chain transaction, without updating the malware already running in victim environments.
ChainDrop, linked by researchers to the Shai-Hulud code lineage, infected more than 400 npm packages, including widely used dependencies such as keyv and cacheable-request.
Its targets extend beyond credentials stored in files. ChainDrop searches the memory of GitHub Actions Runner.Worker processes for ephemeral OpenID Connect tokens and CI runner secrets credentials that may never be written to disk and can disappear when a job completes.
It also steals npm and GitHub tokens, SSH keys, cloud credentials, Kubernetes tokens, Terraform state, Vault tokens and AI coding-tool artifacts.
The malware establishes persistence in developer workflows by planting VS Code tasks and Claude Code session hooks.
This turns routine actions such as opening a project folder or launching an AI coding session into malware execution opportunities.

Unit42 Researchers said that, the worm used a malicious preinstall lifecycle hook to download the legitimate Bun runtime and execute a heavily obfuscated credential-stealing payload.
ChainDrop and PolinRider Malware
The worm can also use stolen npm publishing tokens to inject itself into further packages, creating a self-propagating supply-chain compromise.
Mechanisms range from multi-chain transaction queries across networks like TRON, Aptos and Binance Smart Chain (BSC) to zero-data address resolution techniques like NullReceiver.
For C2 resolution, ChainDrop uses EtherHiding: it queries an Ethereum smart contract to obtain active exfiltration domains.

Unit 42 observed the operator rotate the worm’s C2 configuration through one Ethereum transaction, illustrating why a domain block alone may not contain the threat unless defenders track the resolver contract and related blockchain requests.
PolinRider demonstrates the same operational model across a broader developer ecosystem.
The loader queries an actor-controlled wallet for its latest zero-value transaction. It mathematically extracts the active C2 IPv4 address directly from the 20-byte recipient address structure itself.
Socket identified 162 malicious release artifacts across 108 packages and extensions spanning npm, Go modules, Packagist and Chrome extensions, linking the activity to the DPRK-associated Contagious Interview/Famous Chollima cluster.

Instead of relying only on package-install scripts, PolinRider hides obfuscated JavaScript loaders in repository configuration files and fake .woff2 font files.
Some variants use VS Code task files configured to execute when a developer opens a workspace.
Others conceal payloads in files such as vite.config.js, while force-pushes and anti-dated commits are used to make malicious modifications appear old or legitimate.
Once active, PolinRider loaders query public RPC services associated with TRON, Aptos and BNB Smart Chain to retrieve encrypted payloads.
This cross-chain design provides redundancy: if defenders block one RPC provider, network or lookup method, the malware can use another path to fetch its next-stage code or C2 information.
Observed follow-on payloads include DEV#POPPER and OmniStealer, which support credential theft, browser-data collection, wallet theft and remote command execution.
Developer workstations and automated build runners routinely hold elevated identities. A stolen OIDC token, cloud session credential or deployment secret can give an attacker access to management APIs and cloud resources without needing to defeat MFA interactively.
The attack therefore shifts initial access from a conventional endpoint compromise to a trusted software dependency executing inside a privileged engineering workflow.
Security teams should baseline whether blockchain or public RPC traffic is legitimate in their environments.
For enterprises with no Web3 requirement, outbound connections to blockchain gateways from build runners, package managers, IDEs, scripting engines or compiler processes should be treated as a high-confidence anomaly.
Teams should also enforce CI egress restrictions, use ephemeral runners, audit package lifecycle hooks and workspace automation files, rebuild affected systems from known-good lockfiles, and rotate exposed cloud, registry, source-control and automation credentials from a clean host
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.