Evolution of Web3 in Cloud Supply Chain Attacks
What happened
If your organization should never connect to a Web3 or blockchain network, this is an easy win. Unit 42 details how threat actors (the person or group behind an attack) leverage Web3 infrastructure and open-source supply chain attack (an attack that reaches a target through software it depends on)s to breach enterprise cloud environments The post Evolution of Web3 in Cloud Supply Chain Attacks appeared first on Unit 42 .
This advancement goes from using static C2 endpoints hard coded in malware (software written to damage a system or steal from it) binaries to using Web3-powered smart contracts (a program that runs on a blockchain and moves funds by its own rules). Threat actors are then enabled to dynamically update entire botnets (a network of hijacked machines controlled by one operator) and worm network infrastructures with a single smart contract transaction.
According to the 2026 Unit 42 Global Incident Response Report , software supply chain compromises have become a leading initial access vector targeting enterprise cloud environments. This operational shift has been seen in North Korea-affiliated state-sponsored actors, such as Alluring Pisces (aka Sapphire Sleet or Midnight Neptune), that operationalize these techniques across their recent attributed supply chain campaigns, including those targeting Axios , Mastra AI and Rust's arrayref.
There are active defensive measures organizations can employ to combat this technique. See the section Considerations for Security Teams for additional information.
Sources & evidence
- Palo Alto Networks Unit 42 Primary / official
Evolution of Web3 in Cloud Supply Chain Attacks โ
https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks/