{"id":2226,"date":"2026-08-05T18:45:33","date_gmt":"2026-08-05T18:45:33","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2226"},"modified":"2026-08-05T18:45:33","modified_gmt":"2026-08-05T18:45:33","slug":"trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2226","title":{"rendered":"Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 05, 2026<\/span><\/span><span class=\"p-tags\">Cyber Espionage \/ Threat Intelligence<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh_jFD4wUBf7wKq8NwAgGKeKgJ3XIR82d26D7t5fNRBoDTOHcK5i66j4VqtLNAvK7Lkocc3lbW4SK33Ialb3F4EuB_k59ahZItRVdPsZ3RceScz5lEyR7gQHqqw221WMj6ArtKDUashxvrkYSPaE0b7ue8v-TkkT0IB8sPhgcCGIqN3mtfsjQ2MKztu5DkV\/s1700-e365\/npm-c2.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.<\/p>\n<p>The new dead drop resolver approach, observed in two trojanized npm packages \u00abbianira-ui\u00bb and \u00abfluid-type-ui,\u00bb has been codenamed <strong><a href=\"https:\/\/opensourcemalware.com\/blog\/nullreceiver-dprk-c2-technique\" target=\"_blank\">NullReceiver<\/a><\/strong> by OpenSourceMalware, which has described it as a \u00abdeliberate improvement on EtherHiding.\u00bb The activity has been linked to North Korea.<\/p>\n<p>The packages are currently no longer available for download from npm. However, statistics show that they have been downloaded a few hundred times since they were first published on July 28, 2026 &#8211;<\/p>\n<ul>\n<li><a href=\"https:\/\/npm-stat.com\/charts.html?package=bianira-ui\" target=\"_blank\">bianira-ui<\/a> (109 downloads), uploaded by an npm user named \u00abnpmuser1101\u00bb<\/li>\n<li><a href=\"https:\/\/npm-stat.com\/charts.html?package=fluid-type-ui\" target=\"_blank\">fluid-type-ui<\/a> (587 downloads), uploaded by an npm user named \u00abnpmuser3002\u00bb<\/li>\n<\/ul>\n<p>EtherHiding was first publicly documented by Guardio Labs in October 2023 as a covert approach that involves embedding nefarious code within a <a href=\"https:\/\/ethereum.org\/developers\/docs\/smart-contracts\/\" target=\"_blank\">smart contract<\/a> on a public blockchain like BNB Smart Chain (BSC) or Ethereum. The technique heralded the \u00abnext level of bulletproof hosting\u00bb as it improves operational resilience in the face of takedowns.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The use of EtherHiding by North Korean hacking groups was detailed by Google Threat Intelligence Group (GTIG) late last year in connection with Contagious Interview, a long-running campaign that aims to deceive potential targets by approaching them on LinkedIn with lucrative job opportunities and asking them to complete an assessment that leads to malware deployment.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The latest development indicates that the threat actors are further refining their tactics and making it difficult for defenders to detect.<\/p>\n<p>\u00abInstead of hardcoding a C2 address or hiding it in transaction <a href=\"https:\/\/crypto.com\/en\/glossary\/calldata\" target=\"_blank\">calldata<\/a> (as in EtherHiding), NullReceiver encodes the C2 IP directly in the bytes of the recipient address of a zero-value, zero-data Ethereum transfer,\u00bb security researcher Paul McCarty said.<\/p>\n<p>\u00abThe malware looks up the attacker&#8217;s wallet, reads the destination address of its most recent outbound transaction, and decodes a C2 IP straight from those address bytes, with no smart contract and no payload field involved.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhp2JlYxtO8ERLKOUQWEHhsEpf5fOczPAzfCYSUfZJCs4_O3vxIogUH1sH3pDS3TnpeQ9ctxXu0QVfTQTdt9I_BfsYl8SaF5cpY_wKimW9-tkgLOE4tYnUr7aSVDnM4d0CEMr4pYT5KiV-_mCYQMzC_vhwRQDTUunVBKiBKjgFiAPMs_A1TSBlWubYasQHK\/s1700-e365\/null.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhp2JlYxtO8ERLKOUQWEHhsEpf5fOczPAzfCYSUfZJCs4_O3vxIogUH1sH3pDS3TnpeQ9ctxXu0QVfTQTdt9I_BfsYl8SaF5cpY_wKimW9-tkgLOE4tYnUr7aSVDnM4d0CEMr4pYT5KiV-_mCYQMzC_vhwRQDTUunVBKiBKjgFiAPMs_A1TSBlWubYasQHK\/s1700-e365\/null.png\" alt=\"\" border=\"0\" data-original-height=\"1080\" data-original-width=\"1449\"\/><\/a><\/div>\n<p>By embedding the C2 IP address in this manner, NullReceiver aims to address one of the major shortcomings of EtherHiding, which requires a fixed, publicly known destination address &#8212; one that can be tracked by defenders as new transactions containing the payload, the C2 IP address, or the malicious script, occur for a gas fee.<\/p>\n<p>NullReceiver, in contrast, provides a non-existent destination address. The address \u00abexists\u00bb only to provide a way to encode the C2 IP address within itself. This, in turn, makes attribution difficult, as it eliminates the \u00abfixed, watchable destination.\u00bb<\/p>\n<p>Neither of the newly discovered npm packages identified as part of the new campaign, bianira-ui and fluid-type-ui, calls a smart contract nor embeds any content within the transaction&#8217;s calldata field. Instead, the JavaScript libraries leverage the new technique to extract the IP address and connect to it. The entire sequence of actions on a victim machine is as follows &#8211;<\/p>\n<ul>\n<li>Look up a hard-coded attacker wallet (\u00ab<a href=\"https:\/\/etherscan.io\/address\/0xa322e5f3d311d3080e6f0121063e9adc2490ef1a\" target=\"_blank\">0xa322e5f3d311d3080e6f0121063e9adc2490ef1a<\/a>\u00ab)<\/li>\n<li>Find its most recent outbound transaction<\/li>\n<li>Read that transaction&#8217;s destination address<\/li>\n<li>Decode a C2 IP address directly out of the address bytes by converting the first four bytes from their hexadecimal representation to their number equivalent<\/li>\n<li>Connect to that IP address (\u00ab166.88.134[.]62\u00bb)<\/li>\n<\/ul>\n<p>An examination of the wallet transactions shows that the destination \u00abTo\u00bb address for each of them is the same: \u00ab<a href=\"https:\/\/etherscan.io\/address\/0xa658863ea658863e68656c6c6f6970626f742121\" target=\"_blank\">0xa658863ea658863e68656c6c6f6970626f742121<\/a>.\u00bb While \u00aba658863e\u00bb becomes \u00ab166.88.134[.]62,\u00bb the trailing bytes \u00ab68656c6c6f6970626f742121\u00bb represent the ASCII string \u00abhelloipbot!!.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>As of writing, a total of 68 transactions have taken place since July 27, 2026, a day before the packages were published.<\/p>\n<p>What makes NullReceiver more sneaky is the absence of a fixed target and a fingerprint, not to mention the fact that the transactions are cheaper than before. A crucial difference between the two techniques is that while EtherHiding makes it possible to smuggle a full URL or script, NullReceiver can only encode a few bytes.<\/p>\n<p>\u00abNullReceiver never reuses a destination,\u00bb OpenSourceMalware said. \u00abEvery lookup is a brand-new, throwaway address that&#8217;s never been seen before. A NullReceiver transaction carries nothing extra at all. There&#8217;s no field to fingerprint, because there&#8217;s no field.\u00bb<\/p>\n<p>\u00abCalldata costs gas per byte. EtherHiding pays for that. NullReceiver&#8217;s transfer is completely blank, making it the cheapest, least conspicuous transaction shape on the network.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 05, 2026Cyber Espionage \/ Threat Intelligence Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2227,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[197,2901,2898,39,2899,35,2900,259],"class_list":["post-2226","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-blockchain","tag-decode","tag-employ","tag-npm","tag-nullreceiver","tag-packages","tag-tactic","tag-trojanized"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2226"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2226\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2227"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}