The Takedown Window Is 86 Minutes, the C2 Is Forever: Unit 42 Maps Web3 Command-and-Control

On 7 October 2026, Palo Alto Networks Unit 42 published Evolution of Web3 in Cloud Supply Chain Attacks, by Eyal Rafian. Its thesis is narrow and worth stating plainly: the interesting change in open-source supply-chain malware is no longer the payload, it is the lookup. Attackers have moved the step where malware learns its command-and-control address off DNS and onto public blockchains, and the published campaigns now resolve C2 through smart contracts, transaction calldata, or — in the newest variant — the recipient field of a transaction that carries no value and no data at all.

We read Unit 42's analysis alongside the primary research it cites: Socket's PolinRider reporting, OpenSourceMalware's NullReceiver write-up, Sonatype's six-package advisory, and the Rust Security Response Team's arrayref post-mortem. Two things surface from that comparison that the summary does not say, and one of them matters for how defenders read attribution in this cluster.

Three phases, described in order, observed in parallel

Unit 42 presents the technique as a three-phase architectural evolution, and as a description of increasing data-minimisation the sequence is correct.

Phase 1, EtherHiding. A hardcoded smart-contract address, queried with read-only eth_call requests, returns a C2 endpoint held in contract state. It defeats DNS sinkholing, but the contract address is a fixed landmark: the outbound JSON-RPC payload names the target contract explicitly in its to field, so controls can block queries to that contract. OpenSourceMalware notes the related detail that EtherHiding implementations reused the well-known burn address 0x000...dEaD, which is precisely how Google Threat Intelligence caught the technique when it tied it to a DPRK-linked actor in October 2025.

Phase 2, cross-chain transaction-data hiding. Encrypted endpoints move into the calldata of ordinary transactions sent to router or burn addresses. The loader parses transaction history, decrypts in memory, and — this is the operationally significant part — the operator can repoint the entire botnet by broadcasting one new transaction, with no change to deployed malware. Unit 42 reports PolinRider variants implementing fallback routes across TRON, Aptos and BNB Smart Chain. Socket's 1 July PolinRider research independently describes the loader reaching the same three chains' public RPC infrastructure, retrieving encrypted second-stage material, decrypting with embedded XOR keys and executing via eval().

Phase 3, NullReceiver. No contract, no calldata, no payload field. The loader queries an actor-controlled wallet for its most recent outbound transaction and derives an IPv4 address arithmetically from the 20-byte recipient address: read the address, verify an ASCII marker, convert the leading four bytes to decimal, connect. Because the transaction moves zero value and carries zero data, content inspection has nothing to inspect.

The ordering is clean. The calendar is not. OpenSourceMalware published NullReceiver on 2 August 2026, in bianira-ui@1.27.0 and fluid-type-ui@2.0.8. Unit 42's own ChainDrop analysis landed on 6 August 2026 and places that worm on EtherHiding — Phase 1 — while describing the adversary silently reconfiguring the worm's entire C2 infrastructure through a single Ethereum transaction late on 4 August. Socket's Phase 2 PolinRider reporting predates both, at 1 July. Sonatype's NullReceiver-family advisory followed on 10 August.

So within a six-week window in mid-2026, all three “phases” were live simultaneously, in campaigns the same report links to overlapping infrastructure. This is our reading, not a Unit 42 claim, and the practical consequence is a planning error worth avoiding: a defender who treats Phase 3 as the current state and retires Phase 1 and 2 detections will miss the largest campaign in the set. ChainDrop infected over 400 npm packages, including keyv and cacheable-request, using the oldest technique on the list. Data-minimisation is a design preference, not a migration schedule.

The attribution labels do not line up

Unit 42 attributes the cluster to Alluring Pisces, which it glosses as Sapphire Sleet or Midnight Neptune, and ties Axios, Mastra AI and arrayref together through matching C2 beacon behaviour, SSL configurations and clustered VPS hosting ranges.

The sources it cites for the Web3 technique itself use different names. OpenSourceMalware and Sonatype both place NullReceiver in the Contagious Interview campaign, with Sonatype adding the Lazarus APT association and confirming the six packages it found share an Ethereum wallet address with the activity OpenSourceMalware documented. Socket links PolinRider to Contagious Interview / Famous Chollima. These are not obviously the same cluster under different vendor naming schemes; Contagious Interview and Sapphire Sleet are usually tracked as distinct DPRK activity sets.

We are not asserting that anyone is wrong. We are flagging that a single blockchain C2 technique now appears under at least two attribution clusters across four vendors, and that the shared-infrastructure evidence Unit 42 offers — beacon behaviour, TLS configuration, VPS ranges — is explicitly summarised rather than published. Unit 42 supplies no domains, IP addresses, certificate values, ATT&CK technique IDs or CVE for this report. That is a defensible editorial choice for a trend piece. It also means the linkage cannot be checked by a reader, and should be carried as a vendor assessment rather than a settled fact.

The arrayref entry illustrates the gap most clearly. Unit 42 writes that the actor “poisoned the arrayref crate on crates.io, using Rust's native compilation hook to execute a second-stage payload.” The Rust Security Response Team's 20 August post describes something adjacent but distinct: the malicious build script lived in a separate crate, proc-macro1, which a republished arrayref was made to depend on. Rust credits the discovery to Nextron Systems GmbH, states explicitly that it does not believe the arrayref author acted maliciously — their machine or credentials were likely compromised — and makes no nation-state attribution at all. The dependency-edge detail is the part defenders need, because scanning a package's own source would not have found it.

Why the economics favour the attacker here

The Rust response also supplies the sharpest number in this story. arrayref@0.3.10 was published at 07:15:00Z and deleted at 08:41:40Z: online for 86 minutes. internment@0.8.7 lasted 90, append-only-vec@0.1.9 lasted 107. That is an excellent registry response by any standard.

It is also the whole problem. Registry takedown is fast and effective against the artifact, and completely inert against the lookup layer. A smart contract cannot be deleted; a wallet's transaction history cannot be revoked; a zero-value transfer on BNB Smart Chain does not respond to abuse reports. Every implant that executed inside those 86 minutes retains a working, operator-updatable C2 path, and ChainDrop demonstrated the update in practice — one transaction, entire infrastructure repointed, no new malware shipped. The industry has optimised the half of the kill chain that can be taken down while the other half moved somewhere takedowns do not reach.

It keeps landing in agent tooling

The AI-development angle is not incidental to this cluster. Unit 42 reports ChainDrop injecting persistent task hooks that fire when a developer opens a project or starts an AI coding session, and searching the memory of running build processes for ephemeral cloud IAM keys, CI/CD worker tokens and short-lived OIDC federation keys before the runner terminates — credentials that leave little trace on disk. Socket describes PolinRider triggering through VS Code task files and concealing loaders in .woff2-disguised files, repository configuration and IDE workspace automation, with git history rewritten via force pushes and anti-dated commits so the visible commit log is an unreliable indicator.

Among Sonatype's six NullReceiver packages are @kolbo/mcp@1.57.1 and agentgui@1.0.1127 — MCP and agent-GUI tooling, hijacked rather than typosquatted, with the loader appended to the end of a file that already existed in the legitimate package. The Mastra campaign targeted AI development workflows directly, as we covered in the June Mastra npm compromise. The pattern is consistent with the TensorLake SDK compromise, whose payload also resolved C2 through an Ethereum contract rather than a hardcoded domain, and with the broader pattern of agents living off the land: the developer environment is the target because it holds credentials that outrank the application.

What to do

  • Decide whether blockchain traffic is ever expected from your build estate. For an organisation with no Web3 business requirement, outbound connections from developer workstations or CI runners to public blockchain RPC gateways are a high-confidence anomaly and the single cheapest detection in this report. Document the decision — it is a bad rule for a Web3 shop.
  • Alert on the process, not just the destination. The signal is a package manager, scripting engine, compiler or language runtime initiating blockchain queries. Correlate originating process, user, workspace and destination; the destination alone will increasingly look ordinary.
  • Keep all three phases in your detections. Contract-address blocklists still catch the largest campaign in this cluster. Add calldata and transaction-history reads, and wallet-history queries, rather than replacing the old rules.
  • Audit the dependency edge, not only the package. The arrayref compromise arrived through a newly added dependency with a malicious build script. Flag manifest changes that introduce new transitive dependencies, and treat preinstall, postinstall and compilation hooks as reviewable code.
  • Treat short-lived credentials as stealable. ChainDrop reads process memory for OIDC and runner tokens. Separate build and deployment identities, scope runner permissions down, and do not assume a credential's lifetime is a control.
  • Baseline workspace automation. VS Code task files, IDE workspace settings and repository configuration are execution paths in both campaigns. Compare against approved baselines, and do not trust a repository's commit history as evidence — Socket documented anti-dated commits specifically to defeat that check.

Verification note: the three-phase model, the eth_call and calldata mechanics, the NullReceiver IPv4 derivation steps, the TRON/Aptos/BNB Smart Chain fallback routing, the ChainDrop memory-scraping and AI-coding-session persistence behaviour, the Axios/Mastra/arrayref linkage and the absence of published IOCs were read first-hand from Unit 42's 7 October report. The ChainDrop figure of 400+ packages, the keyv and cacheable-request names, and the 4 August single-transaction C2 reconfiguration were read from Unit 42's 6 August ChainDrop analysis. PolinRider's 162 artifacts across 108 packages, the 80 Go modules, 10 Packagist packages and one Chrome extension, the .woff2 and whitespace-padding concealment, the VS Code task triggering, the anti-dated commits and the DEV#POPPER and OmniStealer payload names are Socket's 1 July reporting by Karlo Zanki. The bianira-ui and fluid-type-ui package versions, the burn-address detail and the October 2025 Google attribution of EtherHiding are from OpenSourceMalware's 2 August write-up by Paul McCarty, which states no code was executed during analysis. The six-package list, the sonatype-2026-005899 and -005901 identifiers, the shared wallet address, the Blockscout fallback and the /0x/cls and /0x/ls retrieval endpoints are Sonatype's 10 August advisory. The arrayref publication and deletion timestamps, the proc-macro1 dependency mechanism, the Nextron Systems credit and the statement that the author is not believed to have acted maliciously were read from the Rust Security Response Team's 20 August post. The observation that the three phases ran concurrently, the note that the attribution labels differ across these sources, and the takedown-asymmetry argument are our editorial analysis, not claims made by any cited vendor. We did not execute, analyse or retrieve any malware sample, and we performed no blockchain lookups.

Sources: