On October 7, 2026, Palo Alto Networks Unit 42 published research revealing that threat actors are systematically upgrading their command-and-control infrastructure to use Web3 and smart contracts in cloud supply chain attacks.
Web3 Command-and-Control Evolution
According to Unit 42, threat actors have advanced from using static command-and-control endpoints hard-coded in malware binaries to utilizing Web3-powered smart contracts. This allows operators to dynamically update entire botnets and worm network infrastructures with a single smart contract transaction.
Unit 42 outlines three distinct architectural phases in this evolution: EtherHiding, Cross-Chain Transaction Data Hiding, and Zero-Data Address Resolution. These phases move from observable smart contract storage to completely zero-data transaction decoding to bypass traditional network monitoring.
Notable Supply Chain Campaigns
Recent campaigns such as the ChainDrop npm worm and PolinRider demonstrate how open-source packages extract ephemeral cloud access keys and establish persistence. ChainDrop infected over 400 npm packages using a preinstall script hook to download a custom Bun runtime.
North Korea-affiliated state-sponsored actors, including Alluring Pisces, Sapphire Sleet, or Midnight Neptune, have operationalized these techniques across campaigns targeting Axios, Mastra AI, and Rust's arrayref. These operations leverage supply chain poisoning to harvest elevated cloud identity tokens, service account keys, and deployment secrets.
Security Considerations and Defenses
Unit 42 recommends evaluating business domains to determine if Web3 or blockchain network activity is expected, noting that any outbound blockchain interaction in a traditional enterprise represents an anomaly. Organizations should also ensure endpoint protection and network security controls properly monitor process traffic.
Additionally, security teams must automate policy controls across all CI/CD runners and version control systems. Implementing context-aware behavioral analytics, process-contextual inspection, and build pipeline integrity checks helps counter these sophisticated supply chain threats.
What to do
- Evaluate your organization's business domain to determine whether Web3 or blockchain network activity is ever expected.
- Ensure you have endpoint protection and network security controls in place to properly monitor and block processes and their network traffic if they become compromised.
- Automate your policy controls across all CI/CD runners and version control systems in your environment.
- Deploy context-aware and AI-driven behavioral analytics to correlate network telemetry and baseline normal developer traffic.
- Configure endpoint protection and network security controls to perform deep process-level inspection across developer workstations and CI/CD runners.
Key facts and where they come from
- Threat actors have systematically upgraded their command-and-control infrastructure to use Web3.
Threat actors have systematically upgraded their command-and-control (C2) infrastructure to use Web3
- The ChainDrop npm worm infected over 400 npm packages.
Traced to the Shai-Hulud family, ChainDrop infected over 400 npm packages
- North Korea-affiliated actors have operationalized supply chain techniques across campaigns targeting Axios, Mastra AI, and Rust's arrayref.
North Korea-affiliated state-sponsored actors, such as Alluring Pisces (aka Sapphire Sleet or Midnight Neptune), that operationalize these techniques across their recent attributed supply chain campaigns, including those targeting Axios, Mastra AI and Rust's arrayref.
