LIVE FEED
ATLAS OWASP HIGH Significant risk · Prioritise patching RELEVANCE ▲ 6.5

DPRK npm Supply Chain Worm Uses Web3 C2 to Steal Cloud Keys

TL;DR HIGH
  • What happened: DPRK-linked actors deployed a self-spreading npm worm using blockchain smart contracts as dynamic C2 infrastructure.
  • Who's at risk: Software developers and CI/CD pipeline operators are most exposed due to privileged IAM credential access during dependency resolution.
  • Act now: Block all Web3 and blockchain network traffic at the perimeter if your organisation has no legitimate need for it · Audit npm dependencies for unexpected preinstall scripts and enforce package integrity checks in CI/CD runners · Rotate and scope all cloud IAM credentials used in build pipelines and implement short-lived OIDC federation where possible
DPRK npm Supply Chain Worm Uses Web3 C2 to Steal Cloud Keys

Overview

Unit 42 researchers have documented a significant escalation in North Korea-affiliated supply chain operations, centred on the ChainDrop npm worm and the broader PolinRider campaign. What distinguishes these attacks is the replacement of static, hardcoded command-and-control (C2) endpoints with Web3 smart contracts, allowing operators to dynamically redirect exfiltration traffic with a single blockchain transaction — making traditional domain-based blocking largely ineffective. Notably, targeted projects include Mastra AI, a framework used in AI agent development, which introduces a direct pathway from open-source AI tooling into enterprise cloud environments.

Technical Analysis

ChainDrop, attributed to the Shai-Hulud malware family, propagated through over 400 npm packages — including popular dependencies such as keyv and cacheable-request. Upon package installation, a malicious preinstall script is executed that:

  1. Downloads a custom Bun runtime to bypass standard Node.js detection heuristics.
  2. Launches an obfuscated credential harvester that scrapes both disk-resident files and in-memory build process data.
  3. Captures ephemeral cloud IAM keys, CI/CD worker tokens, and short-lived OIDC federation credentials before the runner terminates.

For C2 resilience, ChainDrop implements EtherHiding — a technique in which the malware queries Ethereum smart contract transaction data to retrieve dynamically encrypted exfiltration endpoints. This means infrastructure can be completely rotated by the attacker without touching a single malware binary. Persistent task hooks are then injected to ensure re-execution on subsequent build cycles.

Alluring Pisces (also tracked as Sapphire Sleet or Midnight Neptune), the DPRK-affiliated group assessed responsible, has applied these techniques across campaigns targeting Axios, Mastra AI, and Rust’s arrayref crate.

Framework Mapping

  • AML.T0010 – AI Supply Chain Compromise: Malicious packages inserted into open-source ecosystems used by AI developers.
  • AML.T0115 – Publish Poisoned AI Artifacts: Worm-infected packages published to npm, targeting AI framework dependencies.
  • AML.T0083 – Credentials from AI Agent Configuration: Harvesting of IAM keys and tokens from developer and build environments.
  • LLM05 – Supply Chain Vulnerabilities: Compromise of upstream packages affecting downstream AI tooling consumers.
  • LLM06 – Sensitive Information Disclosure: Exfiltration of cloud identity tokens and deployment secrets.

Impact Assessment

Organisations consuming npm packages in automated CI/CD pipelines face the highest exposure. Harvested IAM credentials can enable lateral movement into cloud environments, privilege escalation, and long-term persistence. The targeting of AI frameworks such as Mastra AI means AI development teams and MLOps pipelines are not insulated from this threat. The use of blockchain C2 significantly raises the cost of defender-side infrastructure takedowns, extending attacker dwell time.

Mitigation & Recommendations

  • Block Web3 traffic proactively: If blockchain connectivity is not a business requirement, implement network-layer blocks against known Web3 RPC endpoints and Ethereum nodes.
  • Enforce preinstall script controls: Use .npmrc configuration (ignore-scripts=true) and enforce this policy across all CI/CD runners.
  • Adopt short-lived credentials: Replace long-lived IAM keys in pipelines with OIDC federation and role assumption with minimal TTLs.
  • Monitor build process memory: Deploy endpoint detection capable of identifying anomalous process injection or credential scraping during build execution.
  • Audit transitive dependencies: Implement software composition analysis (SCA) tooling to surface unexpected or newly introduced packages in the dependency graph.

References

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.