# npm Ecosystem Under Siege: Multi-Campaign Supply-Chain Attacks Using Blockchain Smart Contracts for Takedown-Resistant C2 (EtherHiding)

> Multiple coordinated and self-propagating supply-chain campaigns in 2025–2026 are targeting the npm ecosystem by storing C2 server addresses inside Ethereum, Polygon, and BNB Smart Chain smart contracts at runtime — a takedown-resistant technique called EtherHiding. The most severe incident, ChainDrop (August 4, 2026), poisoned 444 packages (2,212 versions) in under four hours through compromised GitHub maintainer accounts, using an Ethereum mainnet smart contract as a dead-drop resolver. Additional campaigns by Netskope/SmartLoader (Polygon, 2026), Veracode (Ethereum, 54 packages, January 2026), and Socket.dev (Ethereum, 100+ packages, 2026) demonstrate widespread adoption of blockchain-resolved C2 across distinct threat actors.

- **Published:** 2026-08-04T00:00:00Z
- **Last reviewed:** 2026-08-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1866
- **ID:** TL-2026-1866
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** Shai-Hulud
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

## Background and Technique

EtherHiding, first documented by Guardio in October 2023, is a technique where malware retrieves its command-and-control server address from a blockchain smart contract rather than hardcoding an IP or domain. The attacker deploys a simple contract with a public getter function — the malware issues an eth_call (a read-only RPC method that costs no gas) to one or more public RPC endpoints, decodes the ABI-encoded response, and extracts the current C2 address. Since the contract lives immutably on the blockchain and every full node serves its data, there is no central server to seize or domain to sinkhole — the operator updates the C2 by simply calling the contract's setter, and all deployed malware instances immediately resolve the new address on their next beacon cycle.

## ChainDrop Worm (August 4, 2026) — The Most Severe Incident

ChainDrop, documented by StepSecurity, is a self-propagating supply-chain worm and the most destructive manifestation of EtherHiding to date. On August 4, 2026, an attacker compromised the GitHub account of jaredwray — maintainer of the keyv/cacheable ecosystem — and pushed unsigned but plausible commits directly to main without branch protection. The attacker injected setup.mjs (a cross-platform runtime downloader) and Math_Symbol.js (a 727 KB heavily obfuscated stage-2 worm) into 11 core packages under the jaredwray namespace.

The project's own release workflow published keyv@6.0.0 via OIDC Trusted Publishing, generating valid SLSA provenance attestation — the provenance proved which commit was built, but could not prove the commit was authorized. The preinstall hook ("preinstall": "node setup.mjs") fired during every npm install.

setup.mjs detects the operating system (Linux x64/arm64, macOS x64/arm64, Windows x64/arm64) and downloads the official Bun runtime from github.com/oven-sh/bun/releases/download/bun-v1.3.13/ — living off the land with a real, signed binary. Bun then executes Math_Symbol.js, which is protected by three layers of obfuscation: (1) a rotated 1,283-entry string table with a custom charset decoder, (2) anti-tamper Object hardening, and (3) AES-256-GCM encrypted configuration blobs. Runtime analysis recovered 4,613 decoded strings.

The worm resolves C2 from the Ethereum mainnet contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103 via eth_call selector 0x53ed5143, trying 75 public RPC endpoints in order. If the contract is unreachable, it falls back to searching GitHub commits for signed markers (thebeautifulmarchoftime, IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients) to locate fallback infrastructure. The observed exfiltration domain is npm-cache.com, receiving POST requests to /router.

Exfiltration is analyst-proof: gzip(JSON loot) → AES-256-GCM with a random per-run key → RSA-OAEP-SHA256 key wrapping using an embedded public key → base64. Only the operator's private key can decrypt captured traffic. The C2 channel is bidirectional — if the response contains a code field, the worm executes it via eval(), enabling live remote access.

Within four hours, the worm propagated from the 11 initial jaredwray carriers to 433 additional packages across 14+ compromised org namespaces including @servicetitan (141 packages), @onereach (78), @or-sdk (74), @ornikar (42), @qlik (28), @nebula.js (22), and others. Each victim's own npm tokens and GitHub credentials fueled the next infection — the worm publishes malicious packages using the compromised maintainer's OIDC identity and self-generates Sigstore + Rekor provenance bundles. It also planted persistence hooks targeting Claude Code (.claude/settings.json), VS Code (.vscode/tasks.json), and GitHub Copilot workflows.

The worm contains a Russian locale kill switch — if the LANG environment variable indicates Russian, it prints "Exiting as russian language detected!" and halts execution, suggesting CIS-avoidance or Russian-speaking operators. A dead man's switch in the token monitor subsystem fires an attacker payload when a stolen GitHub token is revoked — punishing credential rotation by the victim.

## Netskope SmartLoader Campaign (April–August 2026)

Netskope Threat Labs identified a Malware-as-a-Service NodeJS infostealer campaign distributing fake AI development tools through cloned GitHub repositories. The malware, dubbed SmartLoader, uses a multi-stage loader chain — Stage 1 is obfuscated with Prometheus, Stage 2 with MoonSec, both LuaJIT-based. Instead of hardcoding an IP, SmartLoader queries the Polygon blockchain at contract 0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc using method selector 0x3bc5de30 via public RPCs (polygon.drpc.org, polygon.publicnode.com, rpc-mainnet.matic.quiknode.pro). The contract returns the stager's IP address as a dead-drop resolver — changing the C2 requires only a contract update. Targets were primarily financial services and tech sectors in North America, Asia, and Southern Europe. Malicious GitHub accounts yawalinte and JuliusMAAR served second-stage payloads.

## Veracode 54-Package Campaign (January 2026)

Veracode identified 54 malicious npm packages using Ethereum smart contract 0x527269621503b08191f2744f666bdd997d14ee2b as a dead-drop C2 resolver. The first-stage JavaScript performs system fingerprinting (hostname, CPU count, total memory, network interfaces), beacons to the C2, and establishes persistence via COM hijacking (registry key HKCU\Software\Classes\CLSID\{D4E5F6A7-B8C9-0D1E-2F3A-4B5C6D7E8F90}\InprocServer32). A native Node module (analytics.node) uses Asynchronous Procedure Calls (APC) to execute the second-stage payload from the Cloudflare-fronted C2 domain staticflow-metrics.com. The campaign targets Windows hosts with 5+ CPUs and appears to be an opportunistic cryptocurrency stealer or miner operation.

## Socket.dev Campaign (2026)

Socket.dev uncovered a campaign of 100+ malicious packages, many typosquatting popular libraries (husky→haski, prettier→pretierr, next→neextjs, axios family, web3 tools). The malware queries Ethereum contract 0xa1b40044EBc2794f207D45143Bd82a1B86156c6b (function getString(address)) via ethers.js to retrieve the C2 URL. The C2 server operates at 45.125.67.172:1337 and distributes platform-specific binaries (node-win.exe for Windows, node-linux for Linux, node-macos for macOS). The payload is spawned as a detached background process with process.unref() so the parent can exit cleanly. Russian-language error messages ("Ошибка установки", "Ошибка при получении IP адреса") suggest Russian-speaking developers.

## Trend Micro ClearFake Analysis (May 2026)

Trend Micro analyzed a ClearFake campaign using BNB Smart Chain testnet smart contracts for EtherHiding. Four contracts deployed from wallet 0xd71f4cdC84420d2bd07F50787B4F998b4c2d5290 form the attack chain: Contract A stores base64-encoded JavaScript, Contracts B/C serve platform-specific ClickFix payloads (SectopRAT for Windows, unknown for macOS), and Contract D acts as an on-chain execution tracker confirming each victim compromise. The campaign had been active for nearly a year (first contract deployed May 26, 2025).

## Impact and Significance

The convergence of blockchain immutability with supply-chain malware represents a paradigm shift in C2 resilience. Traditional takedown methods — domain seizure, IP blocking, hosting provider abuse reports — are ineffective against on-chain C2 because the contract data lives on every full node. Mitigation requires defense-in-depth: --ignore-scripts / install script gating, minimum release age policies (3-7 day cooldown), egress allowlists blocking unexpected RPC calls from build pipelines, branch protection requiring PR review for repository owners, and phishing-resistant MFA (passkeys/security keys) for maintainers. The npm registry, GitHub, and cloud providers cannot fully prevent these attacks at the infrastructure level alone.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1546 Event Triggered Execution
- T1547 Boot or Logon Autostart Execution
- T1554 Compromise Host Software Binary
- T1053 Scheduled Task/Job
- T1027 Obfuscated Files or Information
- T1553 Subvert Trust Controls
- T1036 Masquerading
- T1555 Credentials from Password Stores
- T1528 Steal Application Access Token
- T1552 Unsecured Credentials
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1005 Data from Local System
- T1573 Encrypted Channel
- T1588 Obtain Capabilities
- T1071 Application Layer Protocol
- T1565.001 Stored Data Manipulation
- T1559 Inter-Process Communication

## Sources

- [ChainDrop npm Worm — Full Technical Analysis](https://www.stepsecurity.io/blog/chaindrop-npm-worm)
- [Developers in the Crosshairs: Fake AI Tools Deliver Infostealer (Netskope SmartLoader)](https://www.netskope.com/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer)
- [54 New NPM Packages Found Beaconing to C2 Server in Ethereum Smart Contract](https://www.veracode.com/blog/54-new-npm-packages-found-beaconing-to-c2-server-in-ethereum-smart-contract)
- [Massive npm Malware Campaign Leverages Ethereum Smart Contracts](https://socket.dev/blog/massive-npm-malware-campaign-leverages-ethereum-smart-contracts)
- [EtherHiding — Hiding Web2 Malicious Code in Web3 Smart Contracts](https://guard.io/labs/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts)
- [Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet](https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html)
- [EtherHiding: Fake CAPTCHAs, Click-Fix Lures, and Blockchain-Backed Payload Delivery](https://censys.com/blog/etherhiding-fake-captchas-click-fix-lures-blockchain-backed-payload-delivery)
- [Ethereum Contracts Push Malware on npm (colortoolsv2 / mimelib2)](https://www.reversinglabs.com/blog/ethereum-contracts-push-malware-on-npm)
- [EVM/DeFi npm Typosquatting Attack Targeting Ethereum Developers](https://xygeni.com/blog/evm-defi-npm-typosquatting-attack)
- [Netskope Threat Labs IOCs Repository](https://github.com/netskopeoss/NetskopeThreatLabsIOCs)
- [EtherRAT: DPRK Uses Novel Ethereum Implant in React2Shell Attacks](https://sysdig.com/blog/etherrat-dprk-ethereum-implant)
- [New 'EtherHiding' Malware Campaign Targets Binance Smart Chain](https://rewterz.com/rewterz-news/rewterz-threat-alert-new-etherhiding-malware-campaign-targets-binances-smart-chain-active-iocs)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1866
