< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-05T19:11:27+05:30

Advanced Blockchain-Based C2 Technique Using NullReceiver in Trojanized npm Packages

Cybersecurity researchers identified a new technique called NullReceiver, where trojanized npm packages encode C2 IP addresses within Ethereum transaction addresses to evade detection. The method, linked to North Korean threat actors, uses zero-value transactions with non-existent destination addresses to obscure command-and-control communication.

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.

The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by

Read original article

*** END OF TRANSMISSION ***