Attackers Are Using Blockchain Smart Contracts to Keep Control of Poisoned Software Supply Chains
Palo Alto Networks' Unit 42 says threat actors have upgraded how they control malware. Instead of hard-coding fixed command-and-control addresses into malicious files, they now use Web3 smart contracts on decentralised blockchain networks. This lets attackers update entire botnets and worm networks with a single smart contract transaction.
According to the 2026 Unit 42 Global Incident Response Report, software supply chain compromises are now a leading way into enterprise cloud environments. By poisoning open-source dependencies, attackers bypass traditional authentication perimeters and target developer endpoints and CI/CD pipelines (the automated systems that build and deploy software). Campaigns such as the ChainDrop npm worm and PolinRider use open-source packages designed to steal short-lived cloud access keys and stay embedded in developer workflows. North Korea-affiliated group Alluring Pisces (also known as Sapphire Sleet or Midnight Neptune) has used these techniques in campaigns targeting Axios, Mastra AI and Rust's arrayref.
Unit 42 notes that developer workstations and CI/CD runners are highly privileged targets, often holding sensitive or administrative IAM keys and tokens. Its advice: check whether Web3 or blockchain network activity is ever expected in your business, and block it if not. Keep endpoint protection and network controls in place to monitor and block compromised processes, and automate policy controls across all CI/CD runners and version control systems.