unit42.paloaltonetworks.com 7 Oct 2026, 22:00 UTC

Web3 Supply Chain Attacks Target Cloud Credentials in Developer Pipelines

Web3 Supply Chain Attacks Target Cloud Credentials in Developer Pipelines
CyberSIXT Evidence Panel Source marked as original reporting

THREAT actors are increasingly leveraging Web3-enabled cloud supply chain attacks to harvest cloud credentials and access, bypassting traditional perimeters. The article tracks an architectural shift in how initial access is gained: instead of rely­ing on hard-coded C2 endpoints, attackers now use Web3 smart contracts and cross-chain data channels to control and update malicious infrastructure.

In response to security controls, threat actors are moving through three progressively resilient phases—EtherHiding, Cross-Chain TxDataHiding, and Zero-Data Address Resolution (NullReceiver)—to conceal C2 information and sustain persistence across developer workstations, CI/CD runners and build pipelines.

Two high‑impact campaigns illustrate the trend. The ChainDrop npm worm infected more than 400 packages (notably keyv and cacheable-request), hooking a preinstall script to install a Bun runtime and launch a credential harvester. It not only scanned disk and memory for ephemeral cloud IAM keys, CI/CD tokens and short‑lived OIDC keys, but also used EtherHiding to retrieve C2 details from smart contracts, enabling reconfiguration without touching static domains.

The PolinRider operation broadened across npm, Go modules and Packagist, concealing loaders in repository config files and workspace automation; its loaders dynamically resolve C2 endpoints via Web3 lookups across networks such as TRON, Aptos and BSC, with zero‑data and fallback channels to maintain reach even when primary gateways are blocked.

North Korean actors linked to Axios, Mastra AI and the Rust arrayref incident demonstrate a consistent objective: extract cloud tokens and environment secrets from developer workflows and embed long‑term access within enterprise pipelines. Security teams are urged to prioritise contextual analytics, process‑level endpoint and network inspection, and automated build‑pipeline integrity controls to curb these modern supply‑chain threats.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline