This approach lets attackers rotate C2 infrastructure dynamically without updating the malware — they simply issue a new zero-value Ethereum transaction with a new encoded address .
Prior to NullReceiver, DPRK-linked npm packages had already been observed using Ethereum smart contracts as a hidden C2 layer to deliver malware . The progression shows a deliberate strategy: the blockchain's immutability, global availability, and structural legitimacy make it an ideal resilient C2 channel that defenders cannot easily takedown.
On August 4, 2026, Microsoft Threat Intelligence disclosed ChainDrop, a self-propagating npm worm that remains the most aggressive DPRK-linked software supply chain attack to date .
keyv@6.0.0 package preinstall scripts to execute obfuscated payloads (e.g., setup.mjs, math_init.js) that downloaded a credential-harvesting module called Mini Shai-Hulud keyv, flat-cache, and cache-manager, reaching major enterprise ecosystems downstream Important caveat: While the timing and TTPs (targeting npm, credential theft, cryptocurrency motivation) are highly consistent with DPRK activity, ChainDrop has not yet been formally attributed to a specific DPRK subgroup in the same way NullReceiver has been. Microsoft's analysis focuses on the worm's technical anatomy; attribution is still emerging.
Older DPRK npm campaigns — such as the September 2025 hijack of debug, chalk, and axios — relied on phishing maintainers and pushing wallet-draining code into static packages . ChainDrop represents a step-change: it combines credential theft with automated republishing, turning a single compromise into an exponentially growing infection chain that requires no additional social engineering
.
NullReceiver and its predecessors show DPRK actors moving from hardcoded or fast-flux C2 to blockchain-resolved C2. The Ethereum network becomes a global, censorship-resistant, publicly verifiable bulletin board that attackers control financially (via their wallet) rather than infrastructurally (via domains or IPs). This makes takedown nearly impossible without seizing the wallet itself .
Amazon Threat Intelligence linked the debug, chalk, axios, and typo-crypto compromises to the DPRK-linked group Sapphire Sleet (also known as BlueNoroff, Stardust Chollima, and CageyChameleon), noting the use of AI-assisted malware generation and targeted social engineering of open-source maintainers . The PromptMink campaign (Famous Chollima/Shifty Corsair) further demonstrated AI-generated malicious npm packages sustained over seven months across 300+ versions
.
The Shai-Hulud campaign (September 2025 onward) evolved from an npm worm into a cross-ecosystem threat targeting PyPI and other registries, showing that DPRK actors invest in multi-platform persistence .
All of these campaigns share a common goal: cryptocurrency theft. Whether stealing credentials to drain development wallets, hijacking CI/CD pipelines to inject crypto-stealing code, or using blockchain C2 to maintain persistent access — the endgame remains siphoning digital assets to fund the DPRK regime .
| Campaign | Technique | Innovation |
|---|---|---|
| NullReceiver (Aug 2026) | C2 address encoded in zero-value Ethereum transaction to field | Blockchain-resolved C2; blends into normal traffic; no takedown risk |
| ChainDrop (Aug 4, 2026) | Self-propagating worm using stolen npm credentials; 435 packages in 2 hours | First known DPRK worm in npm; automated lateral spread via CI/CD |
| Sapphire Sleet campaigns (2025–2026) | Phished maintainers of debug, chalk, axios; AI-generated malware | Attribution linking 4 major breaches to a single DPRK subgroup |
| Contagious Interview (2024–2026) | Fake job interviews targeting devs; 1,700+ malicious packages across npm, Go, Rust, PHP | Multi-ecosystem scale; persistent social engineering pipeline |
DPRK threat actors have transitioned from opportunistic package squatting to a mature, multi-vector supply chain warfare capability — using Ethereum's blockchain for undetectable C2, self-replicating worms for viral spread, and AI for production-speed malware generation. The NullReceiver and ChainDrop campaigns, both disclosed within days of each other in early August 2026, suggest the operational tempo and technical ambition are accelerating.