Threat actors are increasingly using blockchain networks as resilient command-and-control infrastructure to steal cloud credentials from developer endpoints and CI/CD environments.
Recent campaigns involving the ChainDrop npm worm and the North Korea-linked PolinRider operation show how poisoned open-source packages can harvest short-lived cloud tokens, service-account credentials, deployment secrets, and source-code access tokens while resolving attacker infrastructure through Web3 services.
The shift matters because blockchain-backed C2 removes the static domains and IP addresses defenders traditionally block.
Rather than embedding a fixed server address in malware, attackers can retrieve encrypted C2 details from smart-contract state, blockchain transaction data or even zero-value wallet transfers.
An operator can then redirect compromised hosts to new infrastructure through a single on-chain transaction, without updating the malware already running in victim environments.
ChainDrop, linked by researchers to the Shai-Hulud code lineage, infected more than 400 npm packages, including widely used dependencies such as keyv and cacheable-request.
Its targets extend beyond credentials stored in files. ChainDrop searches the memory of GitHub Actions Runner.Worker processes for ephemeral OpenID Connect tokens and CI runner secrets credentials that may never be written to disk and can disappear when a job completes.
It also steals npm and GitHub tokens, SSH keys, cloud credentials, Kubernetes tokens, Terraform state, Vault tokens and AI coding-tool artifacts.
The malware establishes persistence in developer workflows by planting VS Code tasks and Claude Code session hooks.
This turns routine actions such as opening a project folder or launching an AI coding session into malware execution opportunities.
Unit42 Researchers said that, the worm used a malicious preinstall lifecycle hook to download the legitimate Bun runtime and execute a heavily obfuscated credential-stealing payload.
The worm can also use stolen npm publishing tokens to inject itself into further packages, creating a self-propagating supply-chain compromise.
Mechanisms range from multi-chain transaction queries across networks like TRON, Aptos and Binance Smart Chain (BSC) to zero-data address resolution techniques like NullReceiver.
For C2 resolution, ChainDrop uses EtherHiding: it queries an Ethereum smart contract to obtain active exfiltration domains.
Unit 42 observed the operator rotate the worm’s C2 configuration through one Ethereum transaction, illustrating why a domain block alone may not contain the threat unless defenders track the resolver contract and related blockchain requests.
PolinRider demonstrates the same operational model across a broader developer ecosystem.
The loader queries an actor-controlled wallet for its latest zero-value transaction. It mathematically extracts the active C2 IPv4 address directly from the 20-byte recipient address structure itself.
Socket identified 162 malicious release artifacts across 108 packages and extensions spanning npm, Go modules, Packagist and Chrome extensions, linking the activity to the DPRK-associated Contagious Interview/Famous Chollima cluster.
Instead of relying only on package-install scripts, PolinRider hides obfuscated JavaScript loaders in repository configuration files and fake .woff2 font files.
Some variants use VS Code task files configured to execute when a developer opens a workspace.
Others conceal payloads in files such as vite.config.js, while force-pushes and anti-dated commits are used to make malicious modifications appear old or legitimate.
Once active, PolinRider loaders query public RPC services associated with TRON, Aptos and BNB Smart Chain to retrieve encrypted payloads.
This cross-chain design provides redundancy: if defenders block one RPC provider, network or lookup method, the malware can use another path to fetch its next-stage code or C2 information.
Observed follow-on payloads include DEV#POPPER and OmniStealer, which support credential theft, browser-data collection, wallet theft and remote command execution.
Developer workstations and automated build runners routinely hold elevated identities. A stolen OIDC token, cloud session credential or deployment secret can give an attacker access to management APIs and cloud resources without needing to defeat MFA interactively.
The attack therefore shifts initial access from a conventional endpoint compromise to a trusted software dependency executing inside a privileged engineering workflow.
Security teams should baseline whether blockchain or public RPC traffic is legitimate in their environments.
For enterprises with no Web3 requirement, outbound connections to blockchain gateways from build runners, package managers, IDEs, scripting engines or compiler processes should be treated as a high-confidence anomaly.
Teams should also enforce CI egress restrictions, use ephemeral runners, audit package lifecycle hooks and workspace automation files, rebuild affected systems from known-good lockfiles, and rotate exposed cloud, registry, source-control and automation credentials from a clean host
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…