news.mlab.sh
Back to the feed
supply-chain

Evolution of Web3 in Cloud Supply Chain Attacks

Medium
Image: Palo Alto Unit 42
Summary

Threat actors are increasingly leveraging Web3 technologies, specifically decentralized blockchain networks, to establish and maintain persistent access to enterprise cloud environments. These techniques involve embedding C2 infrastructure within blockchain transactions and utilizing zero-data transfers to bypass network monitoring. Recent campaigns, including those targeting npm packages and linked to North Korean state-sponsored actors, demonstrate how supply chain poisoning is being used to compromise open-source dependencies and gain long-term administrative access to cloud environments.

Read the full article at Palo Alto Unit 42

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Also covered by 1 other source(s)

Report an error
Confirmed errors are fixed and listed on /corrections.