ChainDrop - EtherHiding C2 + GitHub dead-drop exfil pattern

This one's the interesting bit they're using Ethereum RPC calls as a C2channel and dumping stolen secrets to attacker-owned public repos tagged "Shai-Hulud: Here We Go Again". Also flags Claude/VS Code config file writes dropped by the worm for lateral persistence across dev machines.