Evolution of Web3 in Cloud Supply Chain Attacks
2026-10-07 • Paloalto Networks •
https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks
North Korea-affiliated actors are using poisoned open-source dependencies to steal cloud credentials and establish durable access through developer workstations and CI/CD pipelines. Unit 42 links Alluring Pisces-associated activity across the Axios, Mastra AI and Rust arrayref compromises through matching beacon behavior, SSL configurations and VPS hosting ranges. The broader PolinRider campaign resolves C2 infrastructure through cross-chain transaction data and zero-value blockchain transactions, allowing operators to replace endpoints without modifying deployed loaders. Defenders are advised to flag unexpected blockchain traffic, inspect it in process context and enforce integrity controls across repositories and build systems.