CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3915

As cited

Copy frozen at (site build).

threat intel

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Researchers discovered two malicious npm packages using a new variant of the EtherHiding technique, which hides command-and-control (C2) server IP addresses within fake Ethereum blockchain transactions. The NullReceiver tactic decodes C2 infrastructure from these blockchain-based dead drops, representing an evolution in evasion tactics for supply chain attacks.

Why it matters: JavaScript developers who install bianira-ui or fluid-type-ui packages face immediate compromise and potential C2 communication; practitioners should audit npm dependencies and monitor for similar blockchain-based C2 obfuscation in supply chain artifacts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary