Skip to content
Blockchain C2 Malware Targets Cloud Credentials in Supply Chain Attacks

Blockchain C2 Malware Targets Cloud Credentials in Supply Chain Attacks

First seen 8 Oct 2026, 15:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 16:42 UTC
  • •ChainDrop and PolinRider malware exploit blockchain for resilient C2 infrastructure.
  • •Over 400 npm packages, including key dependencies, have been infected by ChainDrop.
  • •Attackers can harvest sensitive cloud credentials without leaving traces on disk.

Recent campaigns involving the ChainDrop npm worm and the PolinRider operation have exploited blockchain networks as command-and-control (C2) infrastructure to steal cloud credentials from developer environments. These malware variants utilize poisoned open-source packages to harvest sensitive tokens, including OpenID Connect tokens and CI/CD secrets, from compromised systems. ChainDrop has infected over 400 npm packages, including popular dependencies, and can propagate itself through stolen npm publishing tokens. The malware employs advanced techniques such as querying Ethereum smart contracts for C2 details, enabling attackers to rotate their infrastructure without altering the malware code. The PolinRider operation demonstrates similar tactics across a broader developer ecosystem. Researchers emphasize the challenge of defending against these threats due to the dynamic nature of blockchain C2, which complicates traditional domain blocking methods.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-08
ChainDrop and PolinRider malware reported
Researchers disclosed the use of blockchain networks by ChainDrop and PolinRider to steal cloud credentials from developer environments.
Gbhackers
2026-10-08
Malware infects npm packages
ChainDrop has infected more than 400 npm packages, including widely used dependencies like keyv and cacheable-request.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track OmniStealer and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What types of credentials are targeted?
The malware targets cloud credentials, including OpenID Connect tokens, CI/CD secrets, and various access tokens.
How does the malware propagate?
ChainDrop can use stolen npm publishing tokens to inject itself into additional packages, creating a self-propagating threat.
What defenses can be implemented against this threat?
Defenders should monitor for unusual activity in developer environments and consider tracking blockchain transactions related to the malware.