Hackers Use Web3 and Blockchain C2 to Hide Supply Chain Attacks Targeting Cloud Credentials
Unit 42 says the ChainDrop npm worm uses Ethereum smart contracts as C2 to steal cloud and developer credentials.
Unit 42 reported that the ChainDrop npm worm, which infected more than 400 packages, uses an Ethereum smart contract as a dead-drop to learn its data-theft server. A single transaction rotated command-and-control from npm-cache[.]com to awqhnjewqjkl[.]icu without republishing the malware. The worm harvests cloud credentials, npm and GitHub tokens, SSH keys, Kubernetes and Vault tokens, Terraform state, and short-lived GitHub Actions OIDC tokens, and it persists through VS Code tasks and a Claude Code hook. A related North Korea-aligned campaign, PolinRider, used TRON, Aptos, and BNB Smart Chain to fetch encrypted payloads such as DEV#POPPER and OmniStealer.
- ChainDrop infected more than 400 npm packages and steals cloud, GitHub, SSH, and CI tokens.
- An Ethereum contract lets operators rotate C2 domains without republishing packages.
- Persistence uses VS Code tasks and a Claude Code SessionStart hook.
- North Korea-linked PolinRider hides loaders in npm, Go, Packagist, and Chrome extensions.
- Unexpected blockchain traffic from build systems should be treated as suspicious.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | awqhnjewqjkl.icu | d for data theft, then moved its C2 from npm-cache[.]com to awqhnjewqjkl[.]icu through a single Ethereum transaction. The change did not |
| domain | js-mirror.com | ain stored in the original resolver contract list C2 domain js-mirror[.]com Domain stored in the original resolver contract list C2 d |
| domain | npm-cache.com | ain the address used for data theft, then moved its C2 from npm-cache[.]com to awqhnjewqjkl[.]icu through a single Ethereum transacti |
| domain | pypi-get.com | om Earlier active ChainDrop exfiltration endpoint C2 domain pypi-get[.]com Domain stored in the original resolver contract list C2 d |
Full article1,000 words · extracted from cybersecuritynews.com · click to collapse
Threat actors are increasingly turning public blockchain networks into a command-and-control (C2) layer for software supply chain malware, helping them rotate infrastructure without changing the malicious code already running on developer systems.
The method gives criminals a resilient way to direct infected packages toward new data-theft servers while making traditional domain blocklists less effective. The risk is especially serious for cloud-focused organizations.
Poisoned open-source packages can run inside developer laptops and CI/CD pipelines, where they may access temporary cloud identity tokens, deployment secrets, service-account keys, GitHub credentials and other high-value data.
A recent ChainDrop npm worm investigation showed how compromised trusted publishing paths can turn ordinary dependency updates and project settings into a route for credential theft.
Analysts at Unit 42 identified the ChainDrop malware as a self-propagating npm worm that infected more than 400 packages.
The researchers found that it collected cloud credentials, npm and GitHub tokens, SSH keys, Kubernetes tokens, Terraform state files, Vault tokens and secrets stored in developer environments.
It also searched the memory of GitHub Actions runner processes for short-lived OpenID Connect, or OIDC, tokens and runner secrets.
Hackers Use Web3 and Blockchain C2
In a normal malware operation, attackers hard-code a domain or IP address into the malware. That creates a clear target for defenders: security teams can block the address, registrars can suspend the domain, and package platforms can scan the code for it.
Blockchain C2 changes that model. Instead of containing a fixed C2 address, the malware queries a smart contract or blockchain transaction and retrieves the current destination at runtime.
.webp)
ChainDrop used this approach through an Ethereum smart contract. Unit 42 said the worm queried the contract to obtain the address used for data theft, then moved its C2 from npm-cache[.]com to awqhnjewqjkl[.]icu through a single Ethereum transaction.
The change did not require the attackers to republish packages or push a fresh malware version to victims. This technique is commonly called EtherHiding.
It does not mean the blockchain itself is malicious; instead, criminals misuse its public and decentralized design as an address book, payload store or dead-drop service.
A previous EtherHiding malware delivery report described how smart contracts can return encoded JavaScript payloads and let operators change delivery content without modifying a compromised website.
ChainDrop Targets Development Workflows
The ChainDrop infection begins with an altered npm package containing a preinstall command. That command launches setup.mjs, which downloads the legitimate Bun JavaScript runtime if it is absent and uses it to run an obfuscated payload. Bun was not compromised; the threat actors simply used the legitimate runtime to execute their code.
Once active, the malware checks local files, environment variables and cloud metadata services for credentials. It also looks at running build processes, an important detail because CI/CD systems often use temporary credentials that do not remain on disk.
Those tokens can still give attackers a direct path to cloud APIs, deployment environments or source-code systems while they are valid.
ChainDrop also established persistence through developer tools. It wrote a VS Code task that can run when a folder opens and added a Claude Code SessionStart hook.
That means a developer could trigger the malware simply by opening a project or starting an AI coding session. The same risk appears in the developer tool configuration exposure reported around the wider ChainDrop campaign, where trusted local project files became an execution route.
.webp)
A second campaign, tracked as PolinRider, shows that this model is moving beyond npm. Researchers linked the campaign to North Korea-aligned activity and found malicious loaders in npm, Packagist, Go modules and Chrome extensions.
The loaders used blockchain and public RPC services connected to TRON, Aptos and BNB Smart Chain to obtain encrypted follow-on payloads.
The campaign hid its code in files that appeared normal to many developers, including vite.config.js, fake .woff2 font files and .vscode/tasks.json.
This approach matters because many dependency scanning tools focus on package manifests and lockfiles, not editor settings, workspace automation or repository configuration.
The earlier hidden JavaScript loader campaign also showed how PolinRider used such files to deliver DEV#POPPER and OmniStealer payloads.
For defenders, blockchain traffic from build runners and developer endpoints should be treated as a meaningful signal when the organization has no Web3 business need.
Teams should review package lifecycle scripts, inspect repository configuration files, isolate CI runners, restrict outbound connections from build systems and rotate every credential reachable from an affected host.
Indicators of compromise (IoCs):-
| IoC Type | Indicator | Detection Context |
|---|---|---|
| Ethereum smart contract | 0xE1f2395ee43e45A1556EC6438a88c31B83493103 | ChainDrop C2 resolver contract queried through Ethereum RPC services |
| Ethereum transaction | 0xc55920f1bd0531b6738153068a666c080ddded47e6256f1fd980d51c0b507c91 | Transaction used to rotate the ChainDrop C2 domain |
| Ethereum wallet | 0x55F9780ef31cD | Wallet reported as the deployer of the C2 resolver contract |
| C2 domain | npm-cache[.]com | Earlier active ChainDrop exfiltration endpoint |
| C2 domain | pypi-get[.]com | Domain stored in the original resolver contract list |
| C2 domain | js-mirror[.]com | Domain stored in the original resolver contract list |
| C2 domain | awqhnjewqjkl[.]icu | Rotated ChainDrop C2 domain observed after the Ethereum transaction |
| File artifact | .claude/math_init.js | Obfuscated ChainDrop JavaScript payload |
| File artifact | .claude/settings.json | Claude Code SessionStart persistence configuration |
| File artifact | .claude/setup.mjs | Dropper copy used in persistence chain |
| File artifact | .vscode/setup.mjs | Dropper copy linked to VS Code persistence |
| File artifact | .vscode/tasks.json | VS Code task configured to run when a project folder opens |
| File artifact | .github/workflows/codeql_analysis.yml | Malicious workflow template used to serialize GitHub secrets |
| String marker | thebeautifulmarchoftime | GitHub commit-history fallback marker for C2 resolution |
| String marker | IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients | Marker used in commit messages containing stolen tokens |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.