{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/alluring-pisces/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Alluring Pisces"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["supply-chain","cloud-security","C2","blockchain","DPRK"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eUnit 42 research details an evolution in threat actor C2 strategies, specifically focusing on the integration of Web3 and blockchain architectures to bypass traditional network defenses. This trend is heavily utilized by North Korea-affiliated actors, such as Alluring Pisces (also known as Sapphire Sleet or Midnight Neptune). These actors compromise open-source dependencies in the npm, Go, and Rust ecosystems to gain initial access to enterprise cloud environments. By injecting malicious code into packages like Axios, Mastra AI, and the Rust arrayref crate, attackers target developer workstations and CI/CD runners to scrape ephemeral cloud identity tokens, service account keys, and deployment secrets. The C2 infrastructure has moved from static endpoints to sophisticated blockchain-based resolution methods, including EtherHiding, TxDataHiding, and NullReceiver, which effectively hide C2 instructions within standard blockchain transactions to evade conventional network-based threat detection.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker compromises a package maintainer's account or exploits an open-source registry to publish a backdoored dependency.\u003c/li\u003e\n\u003cli\u003eThe target developer or CI/CD system resolves and installs the poisoned dependency, triggering preinstall or compilation hooks.\u003c/li\u003e\n\u003cli\u003eMalware executes within the build process or developer IDE, scanning memory and files for cloud IAM keys, service account credentials, and deployment secrets.\u003c/li\u003e\n\u003cli\u003eThe loader initiates a C2 resolution process by performing JSON-RPC calls to public blockchains (e.g., Ethereum, TRON, or Binance Smart Chain).\u003c/li\u003e\n\u003cli\u003eThe malware parses either smart contract state variables, transaction input data (calldata), or recipient address structures to identify the dynamic C2 IP or domain.\u003c/li\u003e\n\u003cli\u003eThe malware establishes a connection to the retrieved C2 endpoint to exfiltrate the harvested cloud credentials.\u003c/li\u003e\n\u003cli\u003eAttacker uses the stolen high-privilege tokens to gain direct access to cloud management consoles and administrative APIs.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe shift toward Web3-based supply chain attacks allows threat actors to maintain persistent access to highly privileged cloud environments while evading standard network monitoring. Successful compromises result in the theft of administrative identity keys, leading to potential full cloud account takeovers. Recent campaigns have targeted critical development dependencies, impacting organizations relying on modern CI/CD workflows and AI-assisted coding tools. The ability for attackers to dynamically update C2 infrastructure via blockchain transactions ensures long-term operational resilience for these campaigns.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eEvaluate the organizational necessity for blockchain or Web3 network connectivity; if not required, implement network-level egress blocks for known public blockchain RPC endpoints.\u003c/li\u003e\n\u003cli\u003eDeploy endpoint security controls to monitor and block suspicious process behavior originating from build hooks, such as unauthorized memory scanning or unexpected network connections from CI/CD runners.\u003c/li\u003e\n\u003cli\u003eAutomate policy controls within CI/CD pipelines to restrict the use of non-approved or unvetted open-source dependencies.\u003c/li\u003e\n\u003cli\u003eImplement strict secret management practices, ensuring ephemeral cloud identity tokens are scoped with the minimum required permissions and short TTLs to limit the impact of credential theft.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T22:32:09Z","date_published":"2026-10-07T22:32:09Z","id":"https://feed.craftedsignal.io/briefs/2026-10-web3-supply-chain/","summary":"North Korea-affiliated threat actors are leveraging Web3-based command-and-control infrastructure and open-source supply chain poisoning to extract high-privilege cloud credentials from developer environments and CI/CD pipelines.","title":"Evolution of Web3-Based C2 in Cloud Supply Chain Attacks","url":"https://feed.craftedsignal.io/briefs/2026-10-web3-supply-chain/"}],"language":"en","title":"CraftedSignal Threat Feed - Alluring Pisces","version":"https://jsonfeed.org/version/1.1"}