Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Trojanized npm Packages Use Blockchain to Hide C2 IP

Trojanized npm Packages Use Blockchain to Hide C2 IP

Posted on August 5, 2026 By CWS

Cybersecurity experts are currently examining an advanced method known as the NullReceiver tactic, used by trojanized npm packages to obscure the command-and-control (C2) server IP address. This innovation marks an evolution in the EtherHiding technique, which initially utilized blockchain to mask C2 locations. The development was identified in two npm packages, ‘bianira-ui’ and ‘fluid-type-ui,’ which have links to North Korean activities.

Advancements in Blockchain-Based Techniques

The NullReceiver strategy represents a significant leap forward in concealing C2 IP addresses. Unlike EtherHiding, which embeds data within smart contract transactions, NullReceiver encodes the IP address directly into the bytes of a recipient address in a zero-value Ethereum transfer. This method circumvents the need for a fixed, observable destination, making tracking and attribution more difficult for cybersecurity defenders.

The packages employing this tactic were downloaded several hundred times before removal from npm. Specifically, ‘bianira-ui’ and ‘fluid-type-ui’ were downloaded 109 and 587 times, respectively. Despite their removal, these incidents illustrate the evolving tactics of cyber threat actors.

Technical Implementation and Observations

Researchers have detailed the attack sequence facilitated by NullReceiver. The process involves looking up a specific attacker’s wallet, identifying its latest outbound transaction, and decoding the C2 IP from the destination address bytes. The hard-coded wallet and transaction details, such as “0xa322e5f3d311d3080e6f0121063e9adc2490ef1a,” are crucial to this method.

In a technical analysis, the destination “To” address in the transactions translates partially to “166.88.134[.]62,” with residual bytes forming an ASCII string. This finding highlights the sophisticated level of obfuscation employed by the attackers.

The Impact and Future Implications

NullReceiver’s innovation lies in its ability to execute without a persistent target or identifiable characteristics, which represents a significant challenge for network security efforts. The approach also reduces transaction costs compared to its predecessor, EtherHiding, due to the absence of data payloads that incur gas fees.

As cybersecurity measures evolve, threat actors continue to refine their strategies. The NullReceiver tactic exemplifies the ongoing battle between cyber defenders and attackers, underscoring the need for adaptive and innovative security practices to counteract such deceptive methodologies.

The Hacker News Tags:Blockchain, C2 Server, cyber espionage, cyber threats, Cybersecurity, EtherHiding, Google Threat Intelligence, Guardio Labs, Malware, network security, North Korea, npm packages, NullReceiver, OpenSourceMalware, threat intelligence

Post navigation

Previous Post: CISO-Board Communication Gap: Key Findings Revealed
Next Post: Google Blogger Mistakenly Flags Safe Websites as Malware

Related Posts

REVSTEALER Modules Disable Security to Run Crypto Miner REVSTEALER Modules Disable Security to Run Crypto Miner The Hacker News
China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware The Hacker News
Former Black Basta Members Use Microsoft Teams and Python Scripts in 2025 Attacks Former Black Basta Members Use Microsoft Teams and Python Scripts in 2025 Attacks The Hacker News
Magento Flaw Risks RCE and Account Security Magento Flaw Risks RCE and Account Security The Hacker News
TWINLOOT Exploits Microsoft Services for Credential Theft TWINLOOT Exploits Microsoft Services for Credential Theft The Hacker News
How to Integrate AI into Modern SOC Workflows How to Integrate AI into Modern SOC Workflows The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security
  • Identity Visibility: Key to Secure IAM by 2026
  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security
  • Identity Visibility: Key to Secure IAM by 2026
  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark