[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Insights](https://unit42.paloaltonetworks.com/category/insights/ "Insights")
* [General](https://unit42.paloaltonetworks.com/category/general/ "General")  
  [General](https://unit42.paloaltonetworks.com/category/general/)

# Evolution of Web3 in Cloud Supply Chain Attacks

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read  
Related Products  
[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Eyal Rafian](https://unit42.paloaltonetworks.com/author/eyal-rafian/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:October 7, 2026

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [General](https://unit42.paloaltonetworks.com/category/general/)
  * [Insights](https://unit42.paloaltonetworks.com/category/insights/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Cloud configuration](https://unit42.paloaltonetworks.com/tag/cloud-configuration/)
  * [DPRK](https://unit42.paloaltonetworks.com/tag/dprk/)
  * [Supply-chain attack](https://unit42.paloaltonetworks.com/tag/supply-chain-attack/)
  * [Web3](https://unit42.paloaltonetworks.com/tag/web3/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks/?pdf=download&lg=en&_wpnonce=3406954797 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks/?pdf=print&lg=en&_wpnonce=3406954797 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Evolution%20of%20Web3%20in%20Cloud%20Supply%20Chain%20Attacks&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fweb3-cloud-supply-chain-attacks%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fweb3-cloud-supply-chain-attacks%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fweb3-cloud-supply-chain-attacks%2F&title=Evolution%20of%20Web3%20in%20Cloud%20Supply%20Chain%20Attacks "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fweb3-cloud-supply-chain-attacks%2F&text=Evolution%20of%20Web3%20in%20Cloud%20Supply%20Chain%20Attacks "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fweb3-cloud-supply-chain-attacks%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Evolution%20of%20Web3%20in%20Cloud%20Supply%20Chain%20Attacks%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fweb3-cloud-supply-chain-attacks%2F "Share in Mastodon")

## Executive Summary

Threat actors have systematically upgraded their command-and-control (C2) infrastructure to use [Web3](https://ethereum.org/web3), also known as Web 3.0 or decentralized blockchain web architectures. This advancement goes from using static C2 endpoints hard coded in malware binaries to using Web3-powered smart contracts. Threat actors are then enabled to dynamically update entire botnets and worm network infrastructures with a single smart contract transaction.

According to the [2026 Unit 42 Global Incident Response Report](https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report), software supply chain compromises have become a leading initial access vector targeting enterprise cloud environments. By poisoning open-source dependencies, threat actors bypass traditional authentication perimeters to harvest the following from developer endpoints and continuous integration/continuous deployment (CI/CD) pipelines:

* Elevated cloud identity tokens
* Service account keys
* Deployment secrets

Recent [supply chain campaigns](https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/), most notably the [ChainDrop](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/) npm worm and the [PolinRider](https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands) campaign, demonstrate how open-source packages are engineered specifically to extract ephemeral cloud access keys and establish persistence within developer workflows. This operational shift has been seen in North Korea-affiliated state-sponsored actors, such as [Alluring Pisces](https://unit42.paloaltonetworks.com/threat-assessment-north-korean-threat-groups-2024/) (aka Sapphire Sleet or Midnight Neptune), that operationalize these techniques across their recent attributed supply chain campaigns, including those targeting [Axios](https://unit42.paloaltonetworks.com/axios-supply-chain-attack/), Mastra AI and Rust's arrayref.

So what can be done about this? There are active defensive measures organizations can employ to combat this technique. See the section [Considerations for Security Teams](#post-187943-_wckfc08hz6v9) for additional information.

First, evaluate your organization's business domain to determine whether Web3 or blockchain network activity is ever expected. If your organization should never connect to a Web3 or blockchain network, this is an easy win.

Next, ensure you have endpoint protection and network security controls in place to properly monitor and block processes and their network traffic if they become compromised.

Finally, automate your policy controls across all CI/CD runners and version control systems in your environment.

## Open-Source Supply Chains: The Cloud Initial Access Vector

Developer workstations and automated CI/CD runners represent a highly privileged attack surface holding sensitive or administrative Identity Access Management (IAM) keys or tokens. Current supply chain malware prioritizes extracting these credentials whenever software dependencies are resolved.

Two recent, high-impact campaigns illustrate these cloud-focused initial access vectors with decentralized blockchain C2 methodology.

### ChainDrop npm Worm

Traced to the Shai-Hulud family, [ChainDrop infected over 400](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/) npm packages (including keyv and cacheable-request). The worm executes a preinstall script hook that downloads a custom Bun runtime to launch an obfuscated credential harvester.

In addition to searching static disk files, ChainDrop searches memory inside running build processes. It captures ephemeral cloud provider identity and access management (IAM) keys, CI/CD pipeline worker tokens and short-lived OIDC federation keys. Then, the runner terminates.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/10/word-image-371963-187943-1.png) Figure 1. Attack flow of the ChainDrop npm worm.

To maintain long-term communication without relying on static domains, **ChainDrop uses** [**EtherHiding**](https://guard.io/labs/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts)**to query smart contract transactions**. The smart contract transactions contain dynamically encrypted information for exfiltration IP or domain endpoints. ChainDrop then injects persistent task hooks. This triggers automatic execution whenever a developer opens a project or starts an AI coding session, as shown below in Figure 1.

### PolinRider Campaign

Expanding across developer ecosystems, the PolinRider campaign spans multiple package registries, including npm, Go modules and Packagist. Rather than relying strictly on standard package installation scripts, PolinRider conceals malicious loaders within repository configuration files, web resources and developer IDE workspace automation.

When a developer loads the workspace, the payload silently triggers in the background to exfiltrate developer credentials, cloud session tokens and environment secrets while establishing long-term persistence within enterprise build pipelines.

Across [different variants](https://opensourcemalware.com/blog/chainveil-and-vitevenom-dprk-polinrider-campaign) within the campaign, **loaders dynamically resolve C2 endpoints using Web3 mechanisms**. Mechanisms range from multi-chain transaction queries across networks like TRON, Aptos and Binance Smart Chain (BSC) to zero-data address resolution techniques like NullReceiver.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/10/word-image-374797-187943-2.png) Figure 2. PolinRider multi-registry attack flow and Web3 C2 resolution.

To maximize the reliability of C2 infrastructure, threat actors deploy multiple of these mechanisms in a hybrid architecture. This allows them to use zero-data transfers as a backup channel if primary remote procedure call (RPC) gateways or multi-chain lookups are blocked, as shown below in Figure 2.

Once extracted, these credentials may provide direct access to cloud management consoles and management APIs, bypassing multi-factor authentication (MFA) if other controls are not in place.

## The Architectural Evolution of Web3 Command and Control

Supply chain compromises face a distinct operational hurdle. Once a backdoored package is published to a public registry, automated security scanners, registry auditors and static analysis tools immediately inspect the code for hard-coded C2 domains or IP addresses. Hard coding infrastructure leads to swift domain takedown, IP blocklisting and package removal.

Threat actors can use the Web3 mechanics discussed above to maintain their initial access footholds across developer endpoints and enterprise build pipelines. They can do so by pointing their C2 infrastructure to blockchain networks and, more specifically, to smart contract enabled transactions.

By routing C2 resolution through Web3 networks, campaigns like ChainDrop and DPRK-affiliated PolinRider operations ensure their infrastructure survives Web 2.0-style network monitoring. These techniques have evolved through three distinct architectural phases, moving from observable smart contract storage to completely zero-data transaction decoding.

### Phase 1: EtherHiding

Popularized under the [EtherHiding](https://guard.io/labs/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts) taxonomy and reported in [late 2024 supply chain campaigns targeting npm packages](https://checkmarx.com/uncategorized/supply-chain-attack-using-ethereum-smart-contracts-to-distribute-multi-platform-malware/), early Web3 C2 implementations relied on deploying a hardcoded smart contract address on public blockchains. Malware loaders such as those deployed by the ChainDrop npm worm issued read-only JSON-RPC calls (eth\_call) to retrieve C2 domains stored within smart contract state variables. Although this bypassed traditional Web 2.0 DNS sinkholing, embedding a fixed contract address introduced a static single point of failure. Outbound JSON-RPC request payloads explicitly expose the target contract address ("to": "0x..."). Security controls could flag and block all RPC queries directed to that specific contract.

Reports indicate that the DPRK-affiliated threat actor employs EtherHiding techniques [to distribute malware and steal cryptocurrency](https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding).

### Phase 2: Cross-Chain Transaction Data Hiding (TxDataHiding)

To overcome the single-point-of-failure inherent to hard-coded state contracts, threat actors shifted from contract state storage to the transaction input data layer (calldata). Popularized under the [TxDataHiding](https://ransom-isac.org/blog/cross-chain-txdatahiding-crypto-heist/) taxonomy and deployed across campaigns like PolinRider, this phase decouples C2 resolution from permanent smart contract getters.

Instead of invoking state variables, operators embed encrypted C2 payloads directly into the raw input data fields (0x...) of standard blockchain transactions. The payloads are often sent to dynamic router contracts or designated burn addresses.

The malware loader reads transaction history logs (eth\_getTransactionByHash, or calldata parsing) to extract and decrypt the active payload in memory. In PolinRider, variants implement multi-tier fallback routes across networks like TRON, Aptos and Binance Smart Chain (BSC).

If one chain or router is flagged, the actor broadcasts a fresh transaction on another network, updating global C2 endpoints instantly without modifying a single line of state code.

### Phase 3: Zero-Data Address Resolution (NullReceiver)

Identified in [supply chain compromises](https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads) targeting front-end dependencies (bianira-ui, fluid-type-ui), NullReceiver achieves total data minimization by eliminating smart contracts, input data fields and executable payloads. The loader queries an actor-controlled wallet for its latest zero-value transaction. It mathematically extracts the active C2 IPv4 address directly from the 20-byte recipient address structure itself. Figure 3 demonstrates this below.
![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/10/Screenshot-2026-10-07-at-12.06.35-PM-786x217.png) Figure 3. NullReceiver IPv4 address resolution extraction workflow.

The payload:

* Reads the recipient address
* Verifies the ASCII validation marker
* Converts the leading 4 bytes to decimal
* Connects outbound

Because the transaction carries zero value and zero data, no code structure or domain string exists for security filters to inspect.

## DPRK State-Sponsored Operational Expansion

Cybercriminal groups deploy supply chain worms for opportunistic theft. On the other hand, [North Korean state-sponsored threat actors](https://unit42.paloaltonetworks.com/threat-assessment-north-korean-threat-groups-2024/) use open-source software registries as a primary initial access vector targeting corporate environments.

This strategic shift is reflected across the cloud sector. Recent findings from [Amazon Threat Intelligence](https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/) highlight how North Korean threat groups systematically target open-source dependencies to penetrate enterprise infrastructure.

Threat actors demonstrate how compromising a single maintainer account or registry scope converts open-source dependencies, resulting in widespread affected cloud environments.

Telemetry across these intrusions indicates that an affiliated DPRK threat actor maintained a shared infrastructure footprint.

* [Axios Compromise](https://www.microsoft.com/en-us/security/blog/2026/04/01/mitigating-the-axios-npm-supply-chain-compromise/): The threat actor compromised the lead maintainer of axios, injecting a backdoored dependency (plain-crypto-js) into the package manifest. The payload executed inside enterprise build pipelines to exfiltrate cloud tokens and target macOS code-signing certificates.
* [Mastra AI](https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/) Campaign: Targeting AI development workflows, the threat actor published poisoned npm packages that used build execution hooks to scrape developer environment variables and cloud keys.
* Rust arrayref: Expanding into [Rust](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/), the actor poisoned the arrayref crate on crates.io, using Rust's native compilation hook to execute a second-stage payload upon project builds.

Matching C2 beacon behaviors, SSL configurations, and clustered virtual private server (VPS) hosting ranges link all three operations, demonstrating how the actor leverages supply chain poisoning as a scalable initial access mechanism designed to yield long-lived cloud administrative access.

## Considerations for Security Teams

As threat actors adapt to security controls and evolve beyond zero-data transfers, decentralized C2 techniques will increasingly leverage emergent primitives that blend malicious lookups directly into routine enterprise traffic. When attackers can silently infiltrate developer workstations and build runners to gain their initial foothold, static Indicator of Compromise (IoC) blocklists and traditional perimeter defenses are no longer sufficient to protect cloud infrastructure.

Defending against this threat landscape requires moving from reactive IoC matching to proactive behavioral visibility. Organizations can effectively neutralize these techniques by deploying three core defense capabilities:

#### Context-Aware and AI-Driven Behavioral Analytics

First, evaluate your organization's business domain to determine whether Web3 or blockchain network activity is ever expected within your environment. For typical enterprise organizations without Web3 operations, any outbound blockchain interaction represents an immediate, high-confidence anomaly. Integrating AI-driven behavioral analytics enables security teams to correlate network telemetry, baseline normal developer traffic and determine whether subtle on-chain evasion techniques are actively being witnessed in the environment.

#### Process-Contextual Endpoint and Network Inspection

Configure endpoint protection and network security controls to perform deep process-level inspection across developer workstations and CI/CD runners. Security policies should monitor standard enterprise runtimes, scripting engines and compiler binaries. This raises immediate alerts when non-crypto development tools initiate unexpected outbound queries toward public blockchain gateways.

#### Build Pipeline Integrity

Because modern supply chain payloads conceal loaders within build tools and workspace automation settings, security teams must expand code auditing beyond standard application binaries. Implement automated policy controls across CI/CD runners and version control systems to flag unauthorized modifications to repository configuration files, hidden script injections in package manifests, and unverified package lifecycle hooks before code is executed in build pipelines.

## Additional Resources

* [2026 Unit 42 Global Incident Response Report - Palo Alto Networks](https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report) -- Unit 42, Palo Alto Networks
* [The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)](https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/) -- Unit 42, Palo Alto Networks
* [ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/) -- Unit 42, Palo Alto Networks
* [Threat Brief: Widespread Impact of the Axios Supply Chain Attack](https://unit42.paloaltonetworks.com/axios-supply-chain-attack/) -- Unit 42, Palo Alto Networks
* [Threat Assessment: North Korean Threat Groups](https://unit42.paloaltonetworks.com/threat-assessment-north-korean-threat-groups-2024/) -- Unit 42, Palo Alto Networks
* [PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems | Socket](https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands) -- Socket
* [ChainVeil and ViteVenom are DPRK's PolinRider Campaign | OpenSourceMalware](https://opensourcemalware.com/blog/chainveil-and-vitevenom-dprk-polinrider-campaign) -- OpenSourceMalware
* [Supply Chain Attack Using Ethereum Smart Contracts to Distribute Multi-Platform Malware](https://checkmarx.com/uncategorized/supply-chain-attack-using-ethereum-smart-contracts-to-distribute-multi-platform-malware/) -- Checkmarx
* ["EtherHiding" --- Hiding Web2 Malicious Code in Web3 Smart Contracts](https://guard.io/labs/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts) -- [Guard.io](https://guard.io)
* [Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 1) - Ransom-ISAC](https://ransom-isac.org/blog/cross-chain-txdatahiding-crypto-heist/) -- Ransom-ISAC
* [DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains | Google Cloud Blog](https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding) -- Google
* [Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads](https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads) -- Sonatype
* [Amazon identifies North Korean hacker group behind open-source supply chain attacks | AWS Security Blog](https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/) -- AWS Security
* [Mitigating the Axios npm supply chain compromise | Microsoft Security Blog](https://www.microsoft.com/en-us/security/blog/2026/04/01/mitigating-the-axios-npm-supply-chain-compromise/) -- Microsoft
* [From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet | Microsoft Security Blog](https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/) -- Microsoft
* [Supply chain attack on arrayref | Rust Blog](https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/) -- Rust
  Back to top

### Tags

* [Cloud configuration](https://unit42.paloaltonetworks.com/tag/cloud-configuration/ "cloud configuration")
* [DPRK](https://unit42.paloaltonetworks.com/tag/dprk/ "DPRK")
* [Supply-chain attack](https://unit42.paloaltonetworks.com/tag/supply-chain-attack/ "supply-chain attack")
* [Web3](https://unit42.paloaltonetworks.com/tag/web3/ "Web3")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Blinder Tunnel Campaign Targets Iraqi Infrastructure](https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/ "Blinder Tunnel Campaign Targets Iraqi Infrastructure")

### Table of Contents

* 

### Related Articles

* [Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack](https://unit42.paloaltonetworks.com/new-windows-based-malware-family-airstalk/ "article - table of contents")
* [Extortion and Ransomware Trends January-March 2025](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/ "article - table of contents")
* [False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity Creation](https://unit42.paloaltonetworks.com/north-korean-synthetic-identity-creation/ "article - table of contents")

## Related General Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of a woman in glasses viewing a reflection of a monitor screen. The reflection features multicolored numbers, arrows, and graphs.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/07_Opinion_Overview_1920x900-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 2, 2026 [#### An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation](https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/ "An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation")  
  ![New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_General_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 28, 2026 [#### Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety](https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Jailbreak](https://unit42.paloaltonetworks.com/tag/jailbreak/ "Jailbreak")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/ "Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety")  
  ![Pictorial representation of a male individual viewing multiple monitor screens. The blurred background indicates a female indiviual in the back, also viewing multiple monitor screens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/09_Myth-Busting_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 21, 2026 [#### Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain](https://unit42.paloaltonetworks.com/sdlc-supply-chain/)

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Npm packages](https://unit42.paloaltonetworks.com/tag/npm-packages/ "npm packages")

* [Software supply-chain attack](https://unit42.paloaltonetworks.com/tag/software-supply-chain-attack/ "software supply-chain attack")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/sdlc-supply-chain/ "Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain")  
  ![Pictorial representation of large-scale credential attacks. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 18, 2026 [#### Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)](https://unit42.paloaltonetworks.com/large-scale-credential-attacks/)

* [Credential theft](https://unit42.paloaltonetworks.com/tag/credential-theft/ "credential theft")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/large-scale-credential-attacks/ "Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)")  
  ![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of WebAuthn. A person wearing glasses with computer code reflected in the lenses. The focus is on the eye, and the code is clear and detailed.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Myth-Busting_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) July 2, 2026 [#### How We Added WebAuthn to a Browser-Based RDP Client](https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/)

* [IDA Pro](https://unit42.paloaltonetworks.com/tag/ida-pro/ "IDA Pro")

* [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/ "Microsoft")

* [RDP](https://unit42.paloaltonetworks.com/tag/rdp/ "RDP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/ "How We Added WebAuthn to a Browser-Based RDP Client")  
  ![Pictorial representation of an individual typing on a laptop featuring pop-up screens of lists and tasks.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/11_Listicle_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) June 12, 2026 [#### Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered](https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/)

* [Digital forensics](https://unit42.paloaltonetworks.com/tag/digital-forensics/ "digital forensics")

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/ "Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered")  
  ![Pictorial representation of an aerial view of an individual working on a cumputer in an office setting.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/02_Opinion_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) June 8, 2026 [#### When "Hi, This Is IT" Comes Through Microsoft Teams](https://unit42.paloaltonetworks.com/microsoft-teams-phishing/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Identity](https://unit42.paloaltonetworks.com/tag/identity/ "identity")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/microsoft-teams-phishing/ "When “Hi, This Is IT” Comes Through Microsoft Teams")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* Observability

* [Cortex XCOR](https://www.paloaltonetworks.com/cortex/xcor)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
