Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
thehackernews.com Aug 6, 2026

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

AI-summarised brief · reviewed before publication

Cybersecurity researchers identified a new blockchain‑based command‑and‑control method called NullReceiver, used by trojanized npm packages “bianira‑ui” and “fluid‑type‑ui.” The technique hides a C2 IP address inside the recipient field of a zero‑value Ethereum transfer, eliminating the need for a smart contract or calldata payload. Linked to North Korean actors, the method offers cheaper, harder‑to‑track communications than the earlier EtherHiding approach. The packages, now removed from npm, had been downloaded a few hundred times since their July 28, 2026 release.

💡 Why It Matters

  • · NullReceiver’s use of throwaway, empty transfers removes the fixed target that defenders can monitor, making attribution and disruption significantly harder.
  • · This evolution demonstrates how threat actors continually refine low‑cost, low‑visibility tactics to evade detection.