Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Trojanized npm Packages Use Blockchain to Hide C2 IP

Trojanized npm Packages Use Blockchain to Hide C2 IP

Posted on August 5, 2026 By CWS

Cybersecurity experts are currently examining an advanced method known as the NullReceiver tactic, used by trojanized npm packages to obscure the command-and-control (C2) server IP address. This innovation marks an evolution in the EtherHiding technique, which initially utilized blockchain to mask C2 locations. The development was identified in two npm packages, ‘bianira-ui’ and ‘fluid-type-ui,’ which have links to North Korean activities.

Advancements in Blockchain-Based Techniques

The NullReceiver strategy represents a significant leap forward in concealing C2 IP addresses. Unlike EtherHiding, which embeds data within smart contract transactions, NullReceiver encodes the IP address directly into the bytes of a recipient address in a zero-value Ethereum transfer. This method circumvents the need for a fixed, observable destination, making tracking and attribution more difficult for cybersecurity defenders.

The packages employing this tactic were downloaded several hundred times before removal from npm. Specifically, ‘bianira-ui’ and ‘fluid-type-ui’ were downloaded 109 and 587 times, respectively. Despite their removal, these incidents illustrate the evolving tactics of cyber threat actors.

Technical Implementation and Observations

Researchers have detailed the attack sequence facilitated by NullReceiver. The process involves looking up a specific attacker’s wallet, identifying its latest outbound transaction, and decoding the C2 IP from the destination address bytes. The hard-coded wallet and transaction details, such as “0xa322e5f3d311d3080e6f0121063e9adc2490ef1a,” are crucial to this method.

In a technical analysis, the destination “To” address in the transactions translates partially to “166.88.134[.]62,” with residual bytes forming an ASCII string. This finding highlights the sophisticated level of obfuscation employed by the attackers.

The Impact and Future Implications

NullReceiver’s innovation lies in its ability to execute without a persistent target or identifiable characteristics, which represents a significant challenge for network security efforts. The approach also reduces transaction costs compared to its predecessor, EtherHiding, due to the absence of data payloads that incur gas fees.

As cybersecurity measures evolve, threat actors continue to refine their strategies. The NullReceiver tactic exemplifies the ongoing battle between cyber defenders and attackers, underscoring the need for adaptive and innovative security practices to counteract such deceptive methodologies.

The Hacker News Tags:Blockchain, C2 Server, cyber espionage, cyber threats, Cybersecurity, EtherHiding, Google Threat Intelligence, Guardio Labs, Malware, network security, North Korea, npm packages, NullReceiver, OpenSourceMalware, threat intelligence

Post navigation

Previous Post: CISO-Board Communication Gap: Key Findings Revealed
Next Post: Google Blogger Mistakenly Flags Safe Websites as Malware

Related Posts

Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeover Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeover The Hacker News
Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws The Hacker News
Chaos RAT Malware Targets Windows and Linux via Fake Network Tool Downloads Chaos RAT Malware Targets Windows and Linux via Fake Network Tool Downloads The Hacker News
Worm Code Breach and AI Risks Highlight Cyber Threats Worm Code Breach and AI Risks Highlight Cyber Threats The Hacker News
Microsoft Unveils Tool to Detect AI Model Backdoors Microsoft Unveils Tool to Detect AI Model Backdoors The Hacker News
Update Your cPanel Server to Fix Critical Vulnerability Update Your cPanel Server to Fix Critical Vulnerability The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Blogger Mistakenly Flags Safe Websites as Malware
  • Trojanized npm Packages Use Blockchain to Hide C2 IP
  • CISO-Board Communication Gap: Key Findings Revealed
  • Paperclip AI Vulnerabilities: Critical Security Risks Uncovered
  • Microsoft’s Record $20M Bug Bounty Payout

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Blogger Mistakenly Flags Safe Websites as Malware
  • Trojanized npm Packages Use Blockchain to Hide C2 IP
  • CISO-Board Communication Gap: Key Findings Revealed
  • Paperclip AI Vulnerabilities: Critical Security Risks Uncovered
  • Microsoft’s Record $20M Bug Bounty Payout

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark