Skip to content

Image: unit42.paloaltonetworks.com · rights & removal

Executive Summary

Threat actors are evolving command-and-control (C2) infrastructure to utilize Web3 and decentralized blockchain architectures, moving from static malware endpoints to dynamic smart contract transactions for updating botnets. Software supply chain compromises now serve as a leading initial access vector by poisoning open-source dependencies to harvest sensitive credentials like cloud identity tokens and service account keys from developer workstations and CI/CD pipelines. Campaigns such as ChainDrop npm worm and PolinRider demonstrate the use of Web3 mechanisms for C2, involving transaction queries across networks and zero-data address resolution. The evolution of this technique spans three phases: EtherHiding, which used smart contract state variables; Cross-Chain Transaction Data Hiding, which moved to input data layers like calldata; and Zero-Data Address Resolution, which extracts data directly from transaction addresses. This shift allows threat actors to maintain persistence across network monitoring by routing C2 resolution through blockchain networks.

Facts Only

* Threat actors upgrade C2 infrastructure to use Web3/blockchain architectures.
* Supply chain compromises target enterprise cloud environments via open-source dependency poisoning.
* Compromised systems allow harvesting of cloud identity tokens, service account keys, and deployment secrets from developer endpoints and CI/CD pipelines.
* The ChainDrop npm worm infected over 400 npm packages to execute credential harvesters within build processes.
* ChainDrop used EtherHiding to query smart contract transactions for exfiltration endpoints.
* The PolinRider campaign concealed malicious loaders in repository configuration files and IDE automation.
* Threat actors use Web3 mechanisms, such as multi-chain transaction queries (TRON, Aptos, BSC) or NullReceiver techniques, for C2 resolution.
* Phase 1 involved EtherHiding using read-only JSON-RPC calls to retrieve C2 domains from smart contract state variables.
* Phase 2, TxDataHiding, involves embedding encrypted payloads directly into transaction input data fields (calldata).
* Phase 3, NullReceiver, extracts C2 IPv4 addresses mathematically from zero-value transaction recipient addresses.
* North Korean state-sponsored actors are attributed with operationalizing these techniques in supply chain campaigns targeting Axios, Mastra AI, and Rust's arrayref.

Full Take

The shift toward Web3 command and control represents a fundamental decoupling of persistence mechanisms from easily detectable network infrastructure. The evolution from observable smart contract storage to zero-data transaction decoding reflects a strategic response to the inherent vulnerability of static IoC-based defenses against dynamic adversaries. The pattern reveals a movement where the adversarial goal is not merely access, but survival against post-compromise detection by systematically erasing traceable artifacts across traditional security monitoring layers.
The deployment of techniques like EtherHiding and NullReceiver illustrates an understanding that infrastructure visibility must be bypassed by exploiting cryptographic structures themselves. This suggests a deeper systemic challenge: if control surfaces (like package registries) are compromised, the response must pivot to analyzing the computational primitives used for communication, not just the observable endpoints. The juxtaposition of opportunistic cybercriminal activity (ChainDrop) and state-sponsored operations (DPRK actors) sharing similar technological evolution indicates that these Web3 techniques are becoming a generalized toolkit applicable across different threat actor objectives.
The core implication is that perimeter and static signature defense becomes obsolete when initial access occurs within the development ecosystem, forcing an architectural pivot toward continuous, context-aware behavioral analytics across the entire software lifecycle. The vulnerability lies not just in the artifacts stolen, but in the assumption that traditional network monitoring or code scanning can map activity outside of conventional Web 2.0 protocols.
Bridge Questions: How can organizations establish trust in internal build environments when the mechanisms for establishing and maintaining C2 live on decentralized ledgers? What are the necessary governance structures required to monitor and enforce behavioral baselines across dynamic, ephemeral processes like CI/CD runners? If traditional security controls become insufficient, what new epistemological framework is required to evaluate threat persistence in a fully decentralized environment?

From the original · Unit 42 Palo Alto Networks

Executive Summary Threat actors have systematically upgraded their command-and-control (C2) infrastructure to use Web3, also known as Web 3.0 or decentralized blockchain web architectures. This advancement goes from using static C2 endpoints hard coded in malware binaries to using Web3-powered smart contracts.
Read the full story at unit42.paloaltonetworks.com

Sentinel — Human

Confidence

This analysis reads as highly informed, structured investigative reporting that synthesizes complex technical details regarding supply chain attacks and Web3 C2 evolution.

Signals Detected
low severity: Sentence length variance is relatively varied; the text shifts effectively between dense technical descriptions and directive recommendations.
low severity: The flow successfully transitions from an abstract threat description (Web3 C2) to specific case studies (ChainDrop/PolinRider), architectural evolution, attribution, and concrete defensive recommendations.
low severity: The text effectively weaves disparate case studies and technical phases into a cohesive narrative structure, suggesting careful synthesis rather than simple concatenation of facts.
low severity: Specific campaign names, software package mentions (npm, Rust crates), and the three-phase architectural evolution (EtherHiding, TxDataHiding, NullReceiver) appear highly specific and are referenced with specific external sources, which is characteristic of deep investigative reporting.
Human Indicators
The narrative employs a complex structure that demands synthesizing multiple technical threads rather than presenting a singular, monolithic argument.
The integration of named threat actors (e.g., Alluring Pisces/Sapphire Sleet) and specific attack methodologies shows an understanding beyond surface-level LLM summarization.
The tone balances high-level strategic implications with granular technical detail, indicating a human author grounded in security operations.
Evolution of Web3 in Cloud Supply Chain Attacks | Huntaegis