Blockchain C2 Used in ChainDrop and PolinRider Attacks
Reports say ChainDrop and PolinRider steal cloud and CI credentials using blockchain command-and-control, while threat-actor names differ.
Palo Alto Unit 42 reported on 7 October 2026 that cloud supply-chain attackers moved command-and-control onto Web3 smart contracts, identifying the Shai-Hulud-linked ChainDrop npm worm as infecting more than 400 packages, including keyv and cacheable-request, through a preinstall hook and Bun runtime that harvest ephemeral cloud IAM, CI, and OIDC credentials. GBHackers on 8 October, citing Unit 42, added searches of GitHub Actions Runner.Worker memory and theft of npm, GitHub, SSH, Kubernetes, Terraform, and Vault secrets, plus VS Code and Claude Code persistence and republishing with stolen npm tokens. Cyber Security News later that day said an Ethereum dead-drop rotated ChainDrop command-and-control from npm-cache[.]com to awqhnjewqjkl[.]icu in one transaction without republishing, and named a Claude Code SessionStart hook. PolinRider is described across npm, Go modules, and Packagist, with Unit 42 also citing NullReceiver and GBHackers citing Socket for 162 malicious artifacts in 108 packages plus Chrome; resolution uses TRON, Aptos, and Binance Smart Chain, also called BNB Smart Chain, and GBHackers and Cyber Security News say it delivers DEV#POPPER and OmniStealer. Attribution disagrees: Unit 42 tied related Axios, Mastra AI, and Rust arrayref campaigns to North Korea-linked Alluring Pisces, also known as Sapphire Sleet or Midnight Neptune, while GBHackers called PolinRider DPRK-linked and tied it to Famous Chollima, and Cyber Security News called it North Korea-aligned.
- Palo Alto Unit 42 on 7 October 2026 said Shai-Hulud-linked ChainDrop infected more than 400 npm packages, including keyv and cacheable-request.
- ChainDrop uses a preinstall hook and Bun runtime to harvest cloud IAM, CI, and OIDC credentials from disk and memory, including GitHub Actions Runner.Worker, plus npm, GitHub, SSH, Kubernetes, Terraform, and Vault secrets.
- Cyber Security News said one Ethereum transaction rotated ChainDrop command-and-control from npm-cache[.]com to awqhnjewqjkl[.]icu without republishing the malware.
- Persistence is via VS Code tasks and Claude Code hooks, including a SessionStart hook; stolen npm tokens can republish the worm.
- PolinRider spans npm, Go modules, and Packagist; Socket, cited by GBHackers, counted 162 artifacts in 108 packages and also included Chrome.
- Command-and-control resolution uses TRON, Aptos, and Binance Smart Chain (also called BNB Smart Chain); Unit 42 also named NullReceiver, and GBHackers described EtherHiding via an Ethereum contract.
- GBHackers and Cyber Security News say PolinRider delivers DEV#POPPER and OmniStealer; actor names differ between Alluring Pisces (Sapphire Sleet, Midnight Neptune) and Famous Chollima.
Coverage timelineoldest first · each row is one article
- · 1d agoEvolution of Web3 in Cloud Supply Chain Attacks
Palo Alto Unit 42· 78
Unit 42 says DPRK-linked actors use Web3 smart contracts as C2 for npm worms stealing cloud credentials.
- · 14h agoChainDrop and PolinRider Use Blockchain C2 to Steal Cloud and CI/CD Credentials
GBHackers· 78
ChainDrop and North Korea-linked PolinRider use blockchain C2 to steal cloud and CI/CD credentials.
- · 8h agoHackers Use Web3 and Blockchain C2 to Hide Supply Chain Attacks Targeting Cloud Credentials
Cyber Security News· 79