# Evolution of Web3 in Cloud Supply Chain Attacks: Blockchain Smart-Contract C2 (EtherHiding, TxDataHiding, NullReceiver) in DPRK-Linked npm/Go/Packagist/Rust Campaigns

> Unit 42 reports threat actors have moved command-and-control to Web3 blockchains (EtherHiding, TxDataHiding, NullReceiver), letting them rotate C2 with a single transaction instead of hard-coded endpoints. Campaigns hit npm, Go, Packagist and crates.io to steal cloud, CI/CD and developer credentials, with the PolinRider, Axios, Mastra and arrayref activity attributed to DPRK-affiliated Alluring Pisces (Sapphire Sleet).

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3023
- **ID:** TL-2026-3023
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** APT38 (North Korea)
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Unit 42 (Eyal Rafian, published 2026-10-07) documents a three-stage evolution of blockchain-based C2 used in open-source package poisoning aimed at developer workstations and CI/CD runners.

Stage 1, EtherHiding: malware makes read-only JSON-RPC eth_call queries against a hard-coded smart contract address on a public chain to retrieve the current C2 domain. The static contract address is visible in the request payload ("to": "0x..."), which gives defenders a fixed fingerprint. The ChainDrop npm worm (Shai-Hulud family; Microsoft calls it a Mini Shai-Hulud variant) used this approach: more than 400 npm packages (444 packages / 2,212 versions per secondary reporting, including keyv and cacheable-request) were modified with a preinstall hook that runs a dropper (setup.mjs) which fetches a signed Bun runtime to execute obfuscated code, harvests credentials from disk, process memory and environment (including ephemeral IAM keys and CI tokens), and persists via task hooks that fire when a project or AI coding session is opened. StepSecurity named ChainDrop; reporting indicates it skips Russian-locale hosts.

Stage 2, TxDataHiding: encrypted C2 payloads are embedded in transaction input data (calldata) sent to router contracts or burn addresses and parsed from transaction history (eth_getTransactionByHash), decoupling resolution from permanent contract state. The PolinRider campaign (DPRK-linked, tied to the Contagious Interview / Famous Chollima cluster) uses multi-tier fallback across TRON, Aptos and BSC with hybrid backup channels over multiple RPC gateways. Socket tracks PolinRider across npm, Packagist, Go modules and Chrome extensions (162 package artifacts across 108 packages, first seen 2025-12-07, last activity 2026-06-30), with loaders hidden via whitespace padding, fake .woff2 fonts, VS Code task execution and Git history rewriting. ChainVeil and ViteVenom are DPRK variants tracked by OpenSourceMalware.

Stage 3, NullReceiver: no smart contract and no payload data. Malware looks up the attacker's hard-coded wallet, finds its latest zero-value, zero-data outbound transfer, and decodes an IPv4 C2 address from the bytes of the recipient address. Observed in the npm packages bianira-ui and fluid-type-ui (published 2026-07-28; wallet 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a, decoded C2 166.88.134.62), plus five further packages found later. The malware resolves via public Ethereum RPC providers.

Attribution to Alluring Pisces (aka Sapphire Sleet, Midnight Neptune; BlueNoroff / UNC1069 / Stardust Chollima in other vendor naming) rests on matching C2 beacon behavior across the Axios, Mastra AI and arrayref operations, identical SSL configurations and shared VPS hosting ranges. Axios: a maintainer account was compromised and axios 1.14.1 / 0.30.4 added the dependency plain-crypto-js@4.2.1 that dropped cross-platform RATs from sfrclak.com (Microsoft, 2026-03-31/04-01), targeting enterprise build pipelines and macOS code-signing certificates. Mastra: maintainer account ehindero was used to publish 140+ @mastra packages with the typosquat dependency easy-day-js (disclosed ~2026-06-19). arrayref: on 2026-08-20 the Rust Security Response Team found arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9 republished with a dependency on the typosquat proc-macro1, whose build script downloaded a payload; the malicious versions were online 86-107 minutes. Targets include elevated cloud identity tokens, service account keys, deployment secrets, CI/CD worker tokens, short-lived OIDC federation keys and macOS code-signing certificates; stolen cloud tokens can give direct console access that bypasses MFA where other controls are absent.

No CVEs are assigned. The Unit 42 article itself lists no IOCs; the indicators below come from the cited vendor and community reports.

## MITRE ATT&CK

- T1195.002 Compromise Software Supply Chain
- T1059.007 JavaScript
- T1059.001 PowerShell
- T1059.004 Unix Shell
- T1547.001 Registry Run Keys / Startup Folder
- T1543 Create or Modify System Process
- T1027 Obfuscated Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1552.001 Credentials In Files
- T1003 OS Credential Dumping
- T1528 Steal Application Access Token
- T1555 Credentials from Password Stores
- T1568 Dynamic Resolution

## Sources

- [Evolution of Web3 in Cloud Supply Chain Attacks (Unit 42)](https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks/)
- [Mitigating the Axios npm supply chain compromise (Microsoft Security Blog)](https://www.microsoft.com/en-us/security/blog/2026/04/01/mitigating-the-axios)
- [Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer)](https://bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers)
- [Supply chain attack on arrayref (Rust Blog)](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/)
- [Trojanized npm packages decode C2 IP from Ethereum addresses - NullReceiver (The Hacker News)](https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html)
- [NullReceiver EtherHiding attack: bianira-ui and fluid-type-ui detection guide (Security Arsenal)](https://securityarsenal.com/blog/nullreceiver-etherhiding-attack-trojanized-npm-packages-bianira-ui-and-fluid-type-ui-hide-c2-ips-in-empty-ethereum-transfers-detection-and-removal-guide)
- [ChainDrop, Shai-Hulud and the Anatomy of a Modern npm Supply Chain Worm (SoftwareSeni)](https://www.softwareseni.com/chaindrop-shai-hulud-and-the-anatomy-of-a-modern-npm-worm)
- [ChainDrop: Inside a Self-Propagating npm Worm (OffSeq Threat Radar, citing Unit 42)](https://radar.offseq.com/threat/chaindrop-inside-a-self-propagating-npm-worm-30e4bf623bda4976)
- [PolinRider supply chain attack tracker (Socket)](https://socket.dev/supply-chain-attacks/polinrider)
- [Sapphire Sleet Poisons Mastra AI npm Supply Chain (CSA research note)](https://labs.cloudsecurityalliance.org/research/csa-research-note-sapphire-sleet-mastra-ai-npm-supply-chain/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3023
