news.mlab.sh
Back to the feed
threat-intel

Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

High
Image: The Hacker News
Summary

North Korean hackers are utilizing a new, more sophisticated command-and-control (C2) technique called NullReceiver to evade detection. Instead of embedding a C2 address in a transaction or using a smart contract, NullReceiver encodes the C2 IP address directly within the recipient address of a zero-value Ethereum transfer. This makes attribution significantly more difficult and lowers the cost of operation, as the transactions are cheaper and carry no additional data. The technique was initially linked to the Contagious Interview campaign and has been used in two trojanized npm packages, bianira-ui and fluid-type-ui, which have been downloaded a total of 68 times since their publication on July 27, 2026.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.