EtherHiding: the C2 that keeps its own audit trail
Last month, a coworker of mine was working an IR case and found a payload pulling its command-and-control (C2) config from a contract deployed on the Ethereum testnet - enough to get me digging further. On August 4th, a compromised maintainer account pushed keyv 6.0.0 to npm, and about four hours later the payload inside it had republished itself into 433 other packages, taking the campaign to 2,212 affected versions in all. StepSecurity named it ChainDrop, Wiz traced its lineage back to the Shai-Hulud worms (the self-replicating npm attacks from 2025), and most of the coverage has…