Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
- ID
- 11174
- Status
- summarized
- Published
- 05 Aug 2026, 9:41 PM
- Fetched
- 06 Aug 2026, 1:55 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Excerpt
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by
Summary
No summary yet. It will appear after the daemon summarizes this item.