hacker-news · Crawled Aug 5, 2026
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
8 IoCs
Read original article ↗
AI Summary
Two trojanized npm packages, 'bianira-ui' and 'fluid-type-ui', have been identified as part of a malicious campaign leveraging a novel blockchain-based command-and-control (C2) technique dubbed NullReceiver. This method, attributed to North Korean threat actors, encodes the C2 server IP address within the recipient address of zero-value Ethereum transactions, eliminating the need for smart contracts or calldata payloads. The malware decodes the IP address from the first four bytes of the transaction's destination address and connects to it, with the decoded IP being 166.88.134[.]62. The technique improves stealth and resilience by using throwaway addresses and minimizing on-chain footprint.
AI-extracted · verify before operational use
Indicators of Compromise 8 extracted
| Type | Value | Detail |
|---|---|---|
| Package | bianira-ui | Details → |
| Package | fluid-type-ui | Details → |
| Registry User | npmuser1101 | Details → |
| Registry User | npmuser3002 | Details → |
| IP | 166[.]88[.]134[.]62 | Details → |
| GitHub Repo | OpenSourceMalware/EtherHiding | Details → |
| Registry User | OpenSourceMalware | Details → |
| SHA-256 | a658863ea658863e68656c6c6f6970626f742121 | Details → |