Threat reportSupply ChainTL-2026-3023

Evolution of Web3 in Cloud Supply Chain Attacks: Blockchain Smart-Contract C2 (EtherHiding, TxDataHiding, NullReceiver) in DPRK-Linked npm/Go/Packagist/Rust Campaigns

highACTIVE

Evolution of Web3 in Cloud Supply Chain Attacks (TL-2026-3023), also tracked as ChainDrop, is a high-severity supply-chain compromise, first published 2026-10-07. It is attributed to APT38 (North Korea) with medium confidence, affects npm npm packages (keyv, cacheable-request, axios, plain-crypto-js, maps to 13 MITRE ATT&CK techniques (T1003, T1027, T1036.005), and is covered by 9 detection rules and 32 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
13MITRE ATT&CK
Actors
1APT38
Detection rules
9SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-3023

Threat ID
TL-2026-3023
Also known as
ChainDrop, PolinRider, ChainVeil, ViteVenom, NullReceiver, EtherHiding
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
APT38
Attribution confidence
MEDIUM
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
technology, software-development, cryptocurrency, finance, cloud-services, artificial-intelligence
Target regions
Global
Detection rules
9
Indicators of compromise
32

Malware and tooling in Evolution of Web3 in Cloud Supply Chain Attacks

Malware and tooling: ChainDrop, NullReceiver, PolinRider, Shai-Hulud

How Evolution of Web3 in Cloud Supply Chain Attacks works

Unit 42 reports threat actors have moved command-and-control to Web3 blockchains (EtherHiding, TxDataHiding, NullReceiver), letting them rotate C2 with a single transaction instead of hard-coded endpoints. Campaigns hit npm, Go, Packagist and crates.io to steal cloud, CI/CD and developer credentials, with the PolinRider, Axios, Mastra and arrayref activity attributed to DPRK-affiliated Alluring Pisces (Sapphire Sleet).

Unit 42 (Eyal Rafian, published 2026-10-07) documents a three-stage evolution of blockchain-based C2 used in open-source package poisoning aimed at developer workstations and CI/CD runners.

Stage 1, EtherHiding: malware makes read-only JSON-RPC eth_call queries against a hard-coded smart contract address on a public chain to retrieve the current C2 domain. The static contract address is visible in the request payload ("to": "0x..."), which gives defenders a fixed fingerprint. The ChainDrop npm worm (Shai-Hulud family; Microsoft calls it a Mini Shai-Hulud variant) used this approach: more than 400 npm packages (444 packages / 2,212 versions per secondary reporting, including keyv and cacheable-request) were modified with a preinstall hook that runs a dropper (setup.mjs) which fetches a signed Bun runtime to execute obfuscated code, harvests credentials from disk, process memory and environment (including ephemeral IAM keys and CI tokens), and persists via task hooks that fire when a project or AI coding session is opened. StepSecurity named ChainDrop; reporting indicates it skips Russian-locale hosts.

Stage 2, TxDataHiding: encrypted C2 payloads are embedded in transaction input data (calldata) sent to router contracts or burn addresses and parsed from transaction history (eth_getTransactionByHash), decoupling resolution from permanent contract state. The PolinRider campaign (DPRK-linked, tied to the Contagious Interview / Famous Chollima cluster) uses multi-tier fallback across TRON, Aptos and BSC with hybrid backup channels over multiple RPC gateways. Socket tracks PolinRider across npm, Packagist, Go modules and Chrome extensions (162 package artifacts across 108 packages, first seen 2025-12-07, last activity 2026-06-30), with loaders hidden via whitespace padding, fake .woff2 fonts, VS Code task execution and Git history rewriting. ChainVeil and ViteVenom are DPRK variants tracked by OpenSourceMalware.

Stage 3, NullReceiver: no smart contract and no payload data. Malware looks up the attacker's hard-coded wallet, finds its latest zero-value, zero-data outbound transfer, and decodes an IPv4 C2 address from the bytes of the recipient address. Observed in the npm packages bianira-ui and fluid-type-ui (published 2026-07-28; wallet 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a, decoded C2 166.88.134.62), plus five further packages found later. The malware resolves via public Ethereum RPC providers.

Attribution to Alluring Pisces (aka Sapphire Sleet, Midnight Neptune; BlueNoroff / UNC1069 / Stardust Chollima in other vendor naming) rests on matching C2 beacon behavior across the Axios, Mastra AI and arrayref operations, identical SSL configurations and shared VPS hosting ranges. Axios: a maintainer account was compromised and axios 1.14.1 / 0.30.4 added the dependency plain-crypto-js@4.2.1 that dropped cross-platform RATs from sfrclak.com (Microsoft, 2026-03-31/04-01), targeting enterprise build pipelines and macOS code-signing certificates. Mastra: maintainer account ehindero was used to publish 140+ @mastra packages with the typosquat dependency easy-day-js (disclosed ~2026-06-19). arrayref: on 2026-08-20 the Rust Security Response Team found arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9 republished with a dependency on the typosquat proc-macro1, whose build script downloaded a payload; the malicious versions were online 86-107 minutes. Targets include elevated cloud identity tokens, service account keys, deployment secrets, CI/CD worker tokens, short-lived OIDC federation keys and macOS code-signing certificates; stolen cloud tokens can give direct console access that bypasses MFA where other controls are absent.

No CVEs are assigned. The Unit 42 article itself lists no IOCs; the indicators below come from the cited vendor and community reports.

MITRE ATT&CK techniques used in TL-2026-3023

Credential Access

T1003 OS Credential Dumping; T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1555 Credentials from Password Stores

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location

Execution

T1059.001 PowerShell; T1059.004 Unix Shell; T1059.007 JavaScript

Initial Access

T1195.002 Compromise Software Supply Chain

Persistence

T1543 Create or Modify System Process; T1547.001 Registry Run Keys / Startup Folder

Command and Control

T1568 Dynamic Resolution

Affected products and versions in Evolution of Web3 in Cloud Supply Chain Attacks

  • npm — npm packages (keyv, cacheable-request, axios, plain-crypto-js, @mastra scope, bianira-ui, fluid-type-ui)
    Vulnerable versions: axios 1.14.1; axios 0.30.4; plain-crypto-js 4.2.1
  • Rust / crates.io — arrayref, internment, append-only-vec
    Vulnerable versions: arrayref 0.3.10; internment 0.8.7; append-only-vec 0.1.9
    Fixed in: Malicious versions removed from crates.io on 2026-08-20
  • Packagist / Go modules — PolinRider-compromised packages

Remediation for Evolution of Web3 in Cloud Supply Chain Attacks

Patches

  • Pin axios to a version other than 1.14.1 / 0.30.4
  • Pin arrayref, internment and append-only-vec to versions other than the malicious ones listed by the Rust Security Response Team

Immediate actions

  • Hunt lockfiles, node_modules and ~/.cargo/registry/cache for the affected packages and versions (axios 1.14.1/0.30.4, plain-crypto-js 4.2.1, arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9, easy-day-js, bianira-ui, fluid-type-ui and the other NullReceiver packages)
  • Rotate npm, GitHub Actions, cloud IAM, service account, OIDC and CI/CD secrets on any host or runner that installed an affected package
  • Alert on node, npm, bun, cargo or build-script processes querying public Ethereum/TRON/Aptos/BSC RPC gateways
  • Block sfrclak.com, 142.11.206.73 and 166.88.134.62 at the perimeter

Workarounds

  • Use dependency cooldown periods before adopting newly published package versions
  • Run builds in isolated, egress-restricted runners

Longer-term hardening

  • Disable or review install lifecycle scripts (preinstall/postinstall) in CI and on developer workstations
  • Baseline developer and CI egress and require business justification for blockchain RPC connectivity
  • Audit repository config files, IDE workspace task files and package manifests for hidden loaders
  • Use short-lived, tightly scoped CI credentials and enforce publisher 2FA and trusted publishing

Weaknesses (CWE) in Evolution of Web3 in Cloud Supply Chain Attacks

CWE-506, CWE-829

Timeline of Evolution of Web3 in Cloud Supply Chain Attacks

  • Socket records first discovery of PolinRider, a DPRK-linked multi-ecosystem loader campaign (npm, Packagist, Go modules) that retrieves encrypted second stages from blockchain and public RPC infrastructure.
  • Microsoft identifies malicious axios 1.14.1 and 0.30.4 injecting plain-crypto-js@4.2.1, which downloads cross-platform RATs from sfrclak.com; attributed to Sapphire Sleet.
  • Shai-Hulud worm source code is published (May 2026), enabling reuse by other operators.
  • Maintainer account ehindero is used to publish 140+ malicious @mastra npm packages depending on easy-day-js; Microsoft later attributes the activity to Sapphire Sleet.
  • Last observed PolinRider activity per Socket: 162 package artifacts across 108 unique packages.
  • First NullReceiver transaction from wallet 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a; 68 transactions observed by early August.
  • npm packages bianira-ui and fluid-type-ui are published; five more NullReceiver packages (tailwind-anim variants etc.) are identified later.
  • ChainDrop self-propagating npm worm poisons 444 packages (2,212 versions) in under four hours, using EtherHiding for C2 resolution.
  • Rust Security Response Team removes malicious arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9 and the typosquat crate proc-macro1 after their build script was found downloading a payload.
  • Unit 42 publishes its analysis of the EtherHiding to TxDataHiding to NullReceiver evolution and links the campaigns to Alluring Pisces.

Sources cited for Evolution of Web3 in Cloud Supply Chain Attacks

Detection coverage for TL-2026-3023

As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3023 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-3023

6 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats