National Cyber Warfare Foundation (NCWF)

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain


0 user ratings
2026-08-10 10:22:06
milo
Blue Team (CND)
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.

The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.