Palo Alto Networks' Unit 42 said on 7 October that two recent campaigns look up their control servers on public blockchains. Control servers, called C2, send orders to infected machines. One is the ChainDrop npm worm, which infected over 400 npm packages. The other is PolinRider, which spans npm, Go modules and Packagist and is linked to North Korea.
Unit 42 describes a progression. The first step, EtherHiding, was reported in late 2024 npm campaigns. It read a server address from a smart contract, but that fixed contract address could be blocked. Later, PolinRider variants hid encrypted addresses in ordinary transactions and could post a new one on another chain. NullReceiver, among PolinRider variants, reads an IPv4 address from a wallet address in a zero-value transaction. That transaction has no data or domain string for content filters, so detection depends on seeing which process makes the lookup. Unit 42 gave no count of affected organisations.
ChainDrop searches memory in running build processes for short-lived cloud keys and pipeline tokens, which makes build runners the target. The lookup is a read-only JSON-RPC call to a public gateway, made by a process with no reason to. Unit 42 says lists of known bad indicators and perimeter tools alone fall short. Ask your team: does any runner need blockchain access, and would we notice?