Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
AI-summarised brief · reviewed before publication
Cybersecurity researchers identified a new blockchain‑based command‑and‑control method called NullReceiver, used by trojanized npm packages “bianira‑ui” and “fluid‑type‑ui.” The technique hides a C2 IP address inside the recipient field of a zero‑value Ethereum transfer, eliminating the need for a smart contract or calldata payload. Linked to North Korean actors, the method offers cheaper, harder‑to‑track communications than the earlier EtherHiding approach. The packages, now removed from npm, had been downloaded a few hundred times since their July 28, 2026 release.
💡 Why It Matters
- · NullReceiver’s use of throwaway, empty transfers removes the fixed target that defenders can monitor, making attribution and disruption significantly harder.
- · This evolution demonstrates how threat actors continually refine low‑cost, low‑visibility tactics to evade detection.