hacker-news · Crawled Aug 5, 2026

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

8 IoCs
Read original article ↗

AI Summary

Two trojanized npm packages, 'bianira-ui' and 'fluid-type-ui', have been identified as part of a malicious campaign leveraging a novel blockchain-based command-and-control (C2) technique dubbed NullReceiver. This method, attributed to North Korean threat actors, encodes the C2 server IP address within the recipient address of zero-value Ethereum transactions, eliminating the need for smart contracts or calldata payloads. The malware decodes the IP address from the first four bytes of the transaction's destination address and connects to it, with the decoded IP being 166.88.134[.]62. The technique improves stealth and resilience by using throwaway addresses and minimizing on-chain footprint.

AI-extracted · verify before operational use

Indicators of Compromise 8 extracted

Type Value Detail
Package bianira-ui Details →
Package fluid-type-ui Details →
Registry User npmuser1101 Details →
Registry User npmuser3002 Details →
IP 166[.]88[.]134[.]62 Details →
GitHub Repo OpenSourceMalware/EtherHiding Details →
Registry User OpenSourceMalware Details →
SHA-256 a658863ea658863e68656c6c6f6970626f742121 Details →