Evolution of Web3 in Cloud Supply Chain Attacks

2026-10-07 • Paloalto Networks •

https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks

Thumbnail for Evolution of Web3 in Cloud Supply Chain Attacks

North Korea-affiliated actors are using poisoned open-source dependencies to steal cloud credentials and establish durable access through developer workstations and CI/CD pipelines. Unit 42 links Alluring Pisces-associated activity across the Axios, Mastra AI and Rust arrayref compromises through matching beacon behavior, SSL configurations and VPS hosting ranges. The broader PolinRider campaign resolves C2 infrastructure through cross-chain transaction data and zero-value blockchain transactions, allowing operators to replace endpoints without modifying deployed loaders. Defenders are advised to flag unexpected blockchain traffic, inspect it in process context and enforce integrity controls across repositories and build systems.

Related Actors

Related Reports

« Back