Threat reportSupply ChainTL-2026-1866
npm Ecosystem Under Siege: Multi-Campaign Supply-Chain Attacks Using Blockchain Smart Contracts for Takedown-Resistant C2 (EtherHiding)
npm Ecosystem Under Siege (TL-2026-1866), also tracked as EtherHiding, is a critical-severity supply-chain compromise, first published 2026-08-04. It is attributed to Shai-Hulud with low confidence, affects npm (Node Package Manager) npm Registry, maps to 21 MITRE ATT&CK techniques (T1003, T1005, T1027), and is covered by 9 detection rules and 23 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 21MITRE ATT&CK
- Actors
- 2Shai-Hulud
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-1866
- Threat ID
- TL-2026-1866
- Also known as
- EtherHiding, ChainDrop, SmartLoader, Shai-Hulud 2.0
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Shai-Hulud, ChainDrop Operators
- Attribution confidence
- LOW
- Motivation
- ESPIONAGE
- Target sectors
- technology, finance, software-development, cryptocurrency
- Target regions
- North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in npm Ecosystem Under Siege
Malware and tooling: SmartLoader, Bun Runtime v1.3.13, bsc-testnet-contract-0xA1decFB75C8C0CA28C10517ce56B710baf727d2e, ethereum-contract-0x1f117a1b07c108eae05a5bccbe86922d66227e2b, ethereum-contract-0x527269621503b08191f2744f666bdd997d14ee2b, ethereum-contract-0xE1f2395ee43e45A1556EC6438a88c31B83493103, ethereum-contract-0xa1b40044EBc2794f207D45143Bd82a1B86156c6b, polygon-contract-0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc
How npm Ecosystem Under Siege works
Multiple coordinated and self-propagating supply-chain campaigns in 2025–2026 are targeting the npm ecosystem by storing C2 server addresses inside Ethereum, Polygon, and BNB Smart Chain smart contracts at runtime — a takedown-resistant technique called EtherHiding. The most severe incident, ChainDrop (August 4, 2026), poisoned 444 packages (2,212 versions) in under four hours through compromised GitHub maintainer accounts, using an Ethereum mainnet smart contract as a dead-drop resolver. Additional campaigns by Netskope/SmartLoader (Polygon, 2026), Veracode (Ethereum, 54 packages, January 2026), and Socket.dev (Ethereum, 100+ packages, 2026) demonstrate widespread adoption of blockchain-resolved C2 across distinct threat actors.
## Background and Technique
EtherHiding, first documented by Guardio in October 2023, is a technique where malware retrieves its command-and-control server address from a blockchain smart contract rather than hardcoding an IP or domain. The attacker deploys a simple contract with a public getter function — the malware issues an eth_call (a read-only RPC method that costs no gas) to one or more public RPC endpoints, decodes the ABI-encoded response, and extracts the current C2 address. Since the contract lives immutably on the blockchain and every full node serves its data, there is no central server to seize or domain to sinkhole — the operator updates the C2 by simply calling the contract's setter, and all deployed malware instances immediately resolve the new address on their next beacon cycle.
## ChainDrop Worm (August 4, 2026) — The Most Severe Incident
ChainDrop, documented by StepSecurity, is a self-propagating supply-chain worm and the most destructive manifestation of EtherHiding to date. On August 4, 2026, an attacker compromised the GitHub account of jaredwray — maintainer of the keyv/cacheable ecosystem — and pushed unsigned but plausible commits directly to main without branch protection. The attacker injected setup.mjs (a cross-platform runtime downloader) and Math_Symbol.js (a 727 KB heavily obfuscated stage-2 worm) into 11 core packages under the jaredwray namespace.
The project's own release workflow published keyv@6.0.0 via OIDC Trusted Publishing, generating valid SLSA provenance attestation — the provenance proved which commit was built, but could not prove the commit was authorized. The preinstall hook ("preinstall": "node setup.mjs") fired during every npm install.
setup.mjs detects the operating system (Linux x64/arm64, macOS x64/arm64, Windows x64/arm64) and downloads the official Bun runtime from github.com/oven-sh/bun/releases/download/bun-v1.3.13/ — living off the land with a real, signed binary. Bun then executes Math_Symbol.js, which is protected by three layers of obfuscation: (1) a rotated 1,283-entry string table with a custom charset decoder, (2) anti-tamper Object hardening, and (3) AES-256-GCM encrypted configuration blobs. Runtime analysis recovered 4,613 decoded strings.
The worm resolves C2 from the Ethereum mainnet contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103 via eth_call selector 0x53ed5143, trying 75 public RPC endpoints in order. If the contract is unreachable, it falls back to searching GitHub commits for signed markers (thebeautifulmarchoftime, IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients) to locate fallback infrastructure. The observed exfiltration domain is npm-cache.com, receiving POST requests to /router.
Exfiltration is analyst-proof: gzip(JSON loot) → AES-256-GCM with a random per-run key → RSA-OAEP-SHA256 key wrapping using an embedded public key → base64. Only the operator's private key can decrypt captured traffic. The C2 channel is bidirectional — if the response contains a code field, the worm executes it via eval(), enabling live remote access.
Within four hours, the worm propagated from the 11 initial jaredwray carriers to 433 additional packages across 14+ compromised org namespaces including @servicetitan (141 packages), @onereach (78), @or-sdk (74), @ornikar (42), @qlik (28), @nebula.js (22), and others. Each victim's own npm tokens and GitHub credentials fueled the next infection — the worm publishes malicious packages using the compromised maintainer's OIDC identity and self-generates Sigstore + Rekor provenance bundles. It also planted persistence hooks targeting Claude Code (.claude/settings.json), VS Code (.vscode/tasks.json), and GitHub Copilot workflows.
The worm contains a Russian locale kill switch — if the LANG environment variable indicates Russian, it prints "Exiting as russian language detected!" and halts execution, suggesting CIS-avoidance or Russian-speaking operators. A dead man's switch in the token monitor subsystem fires an attacker payload when a stolen GitHub token is revoked — punishing credential rotation by the victim.
## Netskope SmartLoader Campaign (April–August 2026)
Netskope Threat Labs identified a Malware-as-a-Service NodeJS infostealer campaign distributing fake AI development tools through cloned GitHub repositories. The malware, dubbed SmartLoader, uses a multi-stage loader chain — Stage 1 is obfuscated with Prometheus, Stage 2 with MoonSec, both LuaJIT-based. Instead of hardcoding an IP, SmartLoader queries the Polygon blockchain at contract 0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc using method selector 0x3bc5de30 via public RPCs (polygon.drpc.org, polygon.publicnode.com, rpc-mainnet.matic.quiknode.pro). The contract returns the stager's IP address as a dead-drop resolver — changing the C2 requires only a contract update. Targets were primarily financial services and tech sectors in North America, Asia, and Southern Europe. Malicious GitHub accounts yawalinte and JuliusMAAR served second-stage payloads.
## Veracode 54-Package Campaign (January 2026)
Veracode identified 54 malicious npm packages using Ethereum smart contract 0x527269621503b08191f2744f666bdd997d14ee2b as a dead-drop C2 resolver. The first-stage JavaScript performs system fingerprinting (hostname, CPU count, total memory, network interfaces), beacons to the C2, and establishes persistence via COM hijacking (registry key HKCU\Software\Classes\CLSID\{D4E5F6A7-B8C9-0D1E-2F3A-4B5C6D7E8F90}\InprocServer32). A native Node module (analytics.node) uses Asynchronous Procedure Calls (APC) to execute the second-stage payload from the Cloudflare-fronted C2 domain staticflow-metrics.com. The campaign targets Windows hosts with 5+ CPUs and appears to be an opportunistic cryptocurrency stealer or miner operation.
## Socket.dev Campaign (2026)
Socket.dev uncovered a campaign of 100+ malicious packages, many typosquatting popular libraries (husky→haski, prettier→pretierr, next→neextjs, axios family, web3 tools). The malware queries Ethereum contract 0xa1b40044EBc2794f207D45143Bd82a1B86156c6b (function getString(address)) via ethers.js to retrieve the C2 URL. The C2 server operates at 45.125.67.172:1337 and distributes platform-specific binaries (node-win.exe for Windows, node-linux for Linux, node-macos for macOS). The payload is spawned as a detached background process with process.unref() so the parent can exit cleanly. Russian-language error messages ("Ошибка установки", "Ошибка при получении IP адреса") suggest Russian-speaking developers.
## Trend Micro ClearFake Analysis (May 2026)
Trend Micro analyzed a ClearFake campaign using BNB Smart Chain testnet smart contracts for EtherHiding. Four contracts deployed from wallet 0xd71f4cdC84420d2bd07F50787B4F998b4c2d5290 form the attack chain: Contract A stores base64-encoded JavaScript, Contracts B/C serve platform-specific ClickFix payloads (SectopRAT for Windows, unknown for macOS), and Contract D acts as an on-chain execution tracker confirming each victim compromise. The campaign had been active for nearly a year (first contract deployed May 26, 2025).
## Impact and Significance
The convergence of blockchain immutability with supply-chain malware represents a paradigm shift in C2 resilience. Traditional takedown methods — domain seizure, IP blocking, hosting provider abuse reports — are ineffective against on-chain C2 because the contract data lives on every full node. Mitigation requires defense-in-depth: --ignore-scripts / install script gating, minimum release age policies (3-7 day cooldown), egress allowlists blocking unexpected RPC calls from build pipelines, branch protection requiring PR review for repository owners, and phishing-resistant MFA (passkeys/security keys) for maintainers. The npm registry, GitHub, and cloud providers cannot fully prevent these attacks at the infrastructure level alone.
MITRE ATT&CK techniques used in TL-2026-1866
Credential Access
T1003 OS Credential Dumping; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Persistence
T1053 Scheduled Task/Job; T1546 Event Triggered Execution; T1547 Boot or Logon Autostart Execution; T1554 Compromise Host Software Binary
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution; T1559 Inter-Process Communication
Command and Control
T1071 Application Layer Protocol; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery
Initial Access
defense-impairment
Impact
T1565.001 Stored Data Manipulation
resource-development
Affected products and versions in npm Ecosystem Under Siege
- npm (Node Package Manager) — npm Registry
Vulnerable versions: All versions prior to registry-side preinstall scanning - Ethereum Foundation — Ethereum Mainnet / Public RPC Nodes
Vulnerable versions: All (by-design feature misused by attackers) - Polygon (Matic) — Polygon Blockchain / Public RPC Nodes
Vulnerable versions: All (by-design feature misused by attackers) - BNB Smart Chain — BSC Testnet / Public RPC Nodes
Vulnerable versions: All (by-design feature misused by attackers)
Remediation for npm Ecosystem Under Siege
Immediate actions
- Set npm config ignore-scripts=true in CI/CD pipelines
- Block outbound connections to public blockchain RPC endpoints (ethereum, polygon, bsc) from build environments
- Enforce egress allowlists on CI runners to prevent unauthorized downloads (Bun runtime, second-stage payloads)
- Monitor for npm install events that concurrently fetch Ethereum RPC endpoints
Workarounds
- Use npm --ignore-scripts or npm config set ignore-scripts true for development and CI environments
- Audit all packages for unexpected preinstall/postinstall hooks
- Block npm-cache.com and staticflow-metrics.com at network perimeter
- Implement runtime detection for Node.js/Bun processes making eth_call RPC calls
Longer-term hardening
- Implement minimum release age policies (3-7 day cooldown) on npm packages to allow detection before widespread adoption
- Enable branch protection requiring PR review even for repository owners
- Deploy phishing-resistant MFA (passkeys/security keys) for all npm package maintainers
- Scan for suspicious packages using typosquatting heuristics and blockchain-C2 patterns
- Govern AI agent configuration directories (.claude/, .vscode/) to prevent persistence hooks
Weaknesses (CWE) in npm Ecosystem Under Siege
Timeline of npm Ecosystem Under Siege
- Guardio first documents the EtherHiding technique — malicious JavaScript injected into compromised WordPress sites retrieves payloads from BNB Smart Chain smart contracts via eth_call, bypassing URL-based blocking entirely
- ReversingLabs identifies colortoolsv2 and mimelib2 as the first npm packages using Ethereum smart contracts for C2 resolution, targeting cryptocurrency developers with Ethereum contract 0x1f117a1b07c108eae05a5bccbe86922d66227e2b
- Veracode discovers 54 malicious npm packages (including analytics-browser, anthropic-sdk, clerk-js, framer-motion-js) using Ethereum contract 0x527269621503b08191f2744f666bdd997d14ee2b for C2 resolution, with COM hijacking persistence and APC-based native module injection
- Netskope Threat Labs publishes research on SmartLoader — a MaaS infostealer campaign distributing fake AI developer tools through cloned GitHub repos, using Polygon blockchain contract 0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc for C2 dead-drop resolution
- Trend Micro analyzes ClearFake campaign using BNB Smart Chain testnet for EtherHiding with four smart contracts (deployer wallet 0xd71f4cdC84420d2bd07F50787B4F998b4c2d5290), delivering SectopRAT and ACRStealer via ClickFix overlays
- Xygeni detects 6 typosquatting npm packages (viem-core, hardhat-core-utils, web3-utils-core) targeting Ethereum/Solidity developers; C2 at 76.13.37.80:8443 uses AES-256-GCM with hardcoded passphrase for exfiltration
- 18:10 UTC — All 11 full worm carrier packages reverted to known-good versions; community-wide cleanup and orphaned-org restoration ongoing; estimated 2,212 malicious versions requiring review
- 10:39 UTC — npm Security begins unpublishing malicious versions starting with cacheable-request@13.0.20; GitHub and npm coordinate account recovery and token revocation
- 10:17 UTC — First public alarm raised via jaredwray/cacheable issue #1689; security researchers begin analyzing the worm's Ethereum blockchain C2 and self-replication engine
- 09:38–13:20 UTC — Worm self-propagates from 11 initial carriers to 433 additional packages across 14+ compromised org namespaces (@servicetitan, @onereach, @or-sdk, @ornikar, @qlik, and others) totaling 2,212 malicious versions
- 09:35 UTC — keyv@6.0.0 published via OIDC Trusted Publishing with valid SLSA provenance attestation; preinstall hook fires during npm install, downloading Bun runtime and executing worm payload
- 09:04 UTC — Camouflage commit plants Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) persistence hooks in the keyv repository
- 09:02 UTC — Attacker compromises jaredwray GitHub account, pushes unsigned commit (ee2681a) to keyv main branch containing setup.mjs dropper and Math_Symbol.js stage-2 worm
Sources cited for npm Ecosystem Under Siege
- ChainDrop npm Worm — Full Technical Analysis
- Developers in the Crosshairs: Fake AI Tools Deliver Infostealer (Netskope SmartLoader)
- 54 New NPM Packages Found Beaconing to C2 Server in Ethereum Smart Contract
- Massive npm Malware Campaign Leverages Ethereum Smart Contracts
- EtherHiding — Hiding Web2 Malicious Code in Web3 Smart Contracts
- Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
- EtherHiding: Fake CAPTCHAs, Click-Fix Lures, and Blockchain-Backed Payload Delivery
- Ethereum Contracts Push Malware on npm (colortoolsv2 / mimelib2)
- EVM/DeFi npm Typosquatting Attack Targeting Ethereum Developers
- Netskope Threat Labs IOCs Repository
- EtherRAT: DPRK Uses Novel Ethereum Implant in React2Shell Attacks
- New 'EtherHiding' Malware Campaign Targets Binance Smart Chain
Detection coverage for TL-2026-1866
As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1866 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.