North Korea Runs Cloud Supply Chain Attacks Through the Blockchain, Unit 42 Finds

A close-up of a computer monitor displaying a code editor and a connection-monitoring panel with outbound data.

Stopping a piece of malware usually starts with its command server. Find the domain, take it down, and the implant goes quiet. That only works when there is a domain to take down. North Korea’s operators removed that option. Unit 42, Palo Alto Networks’ threat intelligence team, documents how in new research on cloud supply chain attacks. The group moved its command channel onto a public blockchain, where no domain can be seized and no address blocklisted.

The group is Alluring Pisces (Unit 42), the state-affiliated operation Microsoft tracks as Sapphire Sleet. It resolves its command-and-control (C2) through smart contracts on public chains. Unit 42 ties it to poisoned npm and Rust packages that steal cloud credentials from enterprise build pipelines, then phone home through transactions no takedown can reach.

What ChainDrop and PolinRider steal from the build pipeline

Software supply chain compromise is now a leading way into enterprise cloud environments, the 2026 Unit 42 Global Incident Response Report found. These supply chain breaches target the developer’s own tooling. Workstations and automated continuous integration and continuous deployment (CI/CD) runners hold privileged Identity and Access Management (IAM) keys and short-lived cloud tokens. The malware grabs them the moment a dependency resolves.

ChainDrop is a self-propagating npm worm from the Shai-Hulud family. It infected more than 400 npm packages, including widely used libraries such as keyv and cacheable-request. A preinstall hook installs a credential harvester that reads disk files and the memory of running builds. It lifts cloud IAM keys and CI/CD worker tokens, then shuts the runner down. PolinRider, a related campaign, reaches further, across npm, Go modules, and Packagist. It hides loaders in repository config files and IDE settings, so the payload fires when a developer opens the project. The result is the pattern behind recent cloud supply chain attacks: stolen credentials walk into cloud consoles and bypass multi-factor authentication (MFA) when nothing else is watching.

Why Web3 command and control removes the takedown point

The attacker’s old problem was durability. Once a backdoored package goes public, scanners and registry auditors hunt for hard-coded C2 domains or IP addresses. Those get sinkholed, blocklisted, and pulled within hours. Web3 command and control fixes that. By resolving C2 through smart contracts on public blockchains, the infrastructure outlives ordinary network monitoring. Unit 42 tracks the method through three stages. EtherHiding stored a C2 domain inside an Ethereum smart contract that the malware read on demand. Cross-chain hiding then buried the encrypted address in transaction data across networks like TRON and Binance Smart Chain. NullReceiver, the newest stage, hides the address in the recipient field of a zero-value transaction, leaving no payload, no contract, and no domain to inspect.

That is the shift that matters for defenders. There is no single point left to seize. An operator can broadcast one new transaction on another chain and repoint an entire botnet without touching the deployed package. The short window after a package goes public stops being the defender’s window. Unit 42 attributes this blockchain playbook to North Korea’s Alluring Pisces across three supply chain campaigns. It includes the compromise of the widely used axios npm package, a poisoned set of Mastra AI developer packages, and the arrayref crate on Rust’s registry. Shared beacon behavior and common hosting ranges tie the operations to one actor, which has also used EtherHiding to steal cryptocurrency. One tell survives all of it: for a company with no Web3 business, a build runner reaching a public blockchain is the anomaly.

How to catch a build runner talking to a blockchain

Unit 42’s guidance runs from the cheapest control to the deepest. Each step maps to a stage of the attack.

Treat blockchain traffic as an alert, not a curiosity – For a company with no Web3 business, any outbound connection from a developer endpoint or CI/CD runner to a public blockchain is a high-confidence anomaly. Unit 42 calls this the easy win. It is the one signal NullReceiver cannot erase.

Inspect process behavior on the runner – Static Indicator of Compromise (IoC) blocklists cannot catch a C2 channel with no fixed domain. Configure endpoint and network controls to flag compiler binaries, scripting engines, and package managers that make outbound queries they never normally make. That behavioral view is where practical cloud security now starts.

Audit the build pipeline itself – ChainDrop and PolinRider bury loaders in preinstall hooks and repository config files. Supply chain security has to reach the CI/CD runners and version control systems. Flag unverified lifecycle hooks and unauthorized config changes before any code runs.

Taking down a malicious domain still matters. It no longer ends the story when the next instruction sits in a blockchain transaction. Against this class of cloud supply chain attacks, the win comes earlier and closer to home: a build server, deep in the pipeline, placing a call to a blockchain it had no reason to touch.

Join our LinkedIn group Information Security Community!

Holger Schulze
Holger Schulze is the founder and publisher of Cybersecurity Insiders, an independent cybersecurity research and media company. He writes about how AI is reshaping cybersecurity, where attackers are moving faster than defenses, and what security leaders can do about it. His work draws on original research and real-world incidents, translating both into practical guidance for security teams. Holger moderates the Information Security Community on LinkedIn, one of the largest professional networks in cybersecurity. Connect at linkedin.com/in/holger-schulze

No posts to display