Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean Hackers Conceal Malware in Crypto Transfers

North Korean Hackers Conceal Malware in Crypto Transfers

Posted on August 4, 2026 By CWS

Cybersecurity experts have uncovered a sophisticated method used by North Korean hackers to disguise malware servers within blockchain transactions. This technique is particularly alarming as it obscures the command server addresses within seemingly benign Ethereum transactions, posing a significant risk to unsuspecting developers and their projects.

Malware Concealment in Blockchain Transactions

Recent analyses have identified two npm packages, bianira-ui version 1.27.0 and fluid-type-ui version 2.0.8, as carriers of this new technique. These packages, masquerading as credible Tailwind CSS plugins, pose a threat to software supply chains by delivering hidden malware through routine dependency installations.

The cybersecurity group, OpenSource Malware, has dubbed this method “NullReceiver.” Their investigation links this tactic to the Contagious Interview campaign, a North Korean operation targeting developers with malicious packages under the guise of legitimate software.

Technical Insights and Implications

The NullReceiver method involves extracting the command-and-control server address from an attacker-controlled Ethereum wallet’s latest outgoing transaction. This address, cleverly encoded into the recipient field of a transaction, misleads security systems by resembling ordinary blockchain activity.

Unlike previous methods such as EtherHiding, where command data is embedded within smart contracts, NullReceiver relies on the transaction’s recipient address. This subtlety enables attackers to evade detection, as the transaction doesn’t include any typical indicators of compromise, such as payloads or scripts.

Mitigation Strategies and Developer Risks

The risks associated with such supply chain attacks are profound. Developers inadvertently installing these malicious npm packages could compromise entire build systems and projects. OpenSource Malware’s findings underscore the need for rigorous scrutiny of dependency updates and vigilant monitoring of blockchain RPC traffic.

Organizations are advised to limit access to blockchain RPC providers, quarantine affected systems, and rotate compromised developer credentials. These proactive measures are critical as North Korean cyber campaigns increasingly leverage convincing software decoys to bypass traditional security defenses.

Looking Forward

The emergence of this malware concealment strategy highlights the evolving landscape of cybersecurity threats. As adversaries refine their tactics, the burden on developers and security professionals to identify and mitigate such risks intensifies. Continuous vigilance and adoption of robust security practices will be essential in safeguarding against these sophisticated threats.

Cyber Security News Tags:Blockchain, Contagious Interview, Crypto, cyber threats, Cybersecurity, Developers, Ethereum, Malware, North Korea, NPM, NullReceiver, OpenSource Malware, supply chain

Post navigation

Previous Post: Data Breach at Madera Hospital Affects 150,000 People

Related Posts

CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide Cyber Security News
WAFs protection Bypassed to Execute XSS Payloads Using JS Injection with Parameter Pollution WAFs protection Bypassed to Execute XSS Payloads Using JS Injection with Parameter Pollution Cyber Security News
MuddyWater Hackers Using Custom Malware With Multi-Stage Payloads and Uses Cloudflare to Mask Fingerprints MuddyWater Hackers Using Custom Malware With Multi-Stage Payloads and Uses Cloudflare to Mask Fingerprints Cyber Security News
FBI Warns of Kimsuky Actors Leverage Malicious QR Codes to Target U.S. Organizations FBI Warns of Kimsuky Actors Leverage Malicious QR Codes to Target U.S. Organizations Cyber Security News
North Korean Hackers Exploit Novel Malware for Air-Gapped Systems North Korean Hackers Exploit Novel Malware for Air-Gapped Systems Cyber Security News
CISA Warns of Fortinet FortiWeb WAF Vulnerability Exploited in the Wild to Gain Admin Access CISA Warns of Fortinet FortiWeb WAF Vulnerability Exploited in the Wild to Gain Admin Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korean Hackers Conceal Malware in Crypto Transfers
  • Data Breach at Madera Hospital Affects 150,000 People
  • CISA Alerts on N-able N-central Vulnerability Exploitation
  • Critical Vulnerability in Check Point Systems Requires Immediate Patching
  • Telegram Briefly Removed from Apple App Store Due to Guidelines

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korean Hackers Conceal Malware in Crypto Transfers
  • Data Breach at Madera Hospital Affects 150,000 People
  • CISA Alerts on N-able N-central Vulnerability Exploitation
  • Critical Vulnerability in Check Point Systems Requires Immediate Patching
  • Telegram Briefly Removed from Apple App Store Due to Guidelines

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark