Ethical Hacking News
NullReceiver: A New Threat Intelligence Alert
Researchers have identified two Trojanized npm packages, "bianira-ui" and "fluid-type-ui," that use the NullReceiver tactic to decode C2 IP addresses from blockchain transactions.The NullReceiver tactic represents a more refined and sophisticated approach to C2 communication, using non-existent destination addresses to eliminate attribution.The impact of this new tactic is significant, as it makes it harder for defenders to detect and track C2 IP addresses used by threat actors.Enhanced detection capabilities, advanced threat intelligence tools, and robust security measures are essential to stay ahead of these evolving threats.
In a recent development that has sent shockwaves through the cybersecurity community, researchers have identified two Trojanized npm packages, "bianira-ui" and "fluid-type-ui," that employ the NullReceiver tactic to decode C2 IP addresses from blockchain transactions. This new technique, which has been linked to North Korean hacking groups, has been described by OpenSourceMalware as a "deliberate improvement on EtherHiding." The activity has significant implications for cybersecurity researchers and defenders, who must now contend with a more sophisticated and stealthy method of communication between threat actors.
For those unfamiliar with the context, EtherHiding was first publicly documented by Guardio Labs in October 2023 as a covert approach that involves embedding nefarious code within a smart contract on a public blockchain like BNB Smart Chain (BSC) or Ethereum. The technique has been widely adopted by North Korean hacking groups, who have used it to deceive potential targets and deploy malware.
NullReceiver, on the other hand, represents a more refined and sophisticated approach to C2 communication. This new tactic involves embedding the C2 IP address directly in the bytes of the recipient address of a zero-value, zero-data Ethereum transfer. Unlike EtherHiding, which relies on a fixed destination address that can be tracked by defenders, NullReceiver uses a non-existent destination address that eliminates the need for attribution.
According to security researcher Paul McCarty, "NullReceiver never reuses a destination. Every lookup is a brand-new, throwaway address that's never been seen before. A NullReceiver transaction carries nothing extra at all. There's no field to fingerprint, because there's no field." This makes it significantly harder for defenders to detect and track the C2 IP addresses used by threat actors.
The impact of this new tactic cannot be overstated. As OpenSourceMalware noted, "Calldata costs gas per byte. EtherHiding pays for that. NullReceiver's transfer is completely blank, making it the cheapest, least conspicuous transaction shape on the network." This means that threat actors can now use these transactions to communicate with each other without incurring significant costs or leaving behind any discernible evidence.
The availability of this new technique has significant implications for cybersecurity researchers and defenders. As a result of this development, the following should be considered:
* Enhanced detection capabilities are essential to identify and track NullReceiver-based transactions.
* Researchers must remain vigilant and continue to monitor blockchain activity for signs of this new tactic.
* The use of advanced threat intelligence tools and techniques is necessary to stay ahead of these evolving threats.
* Organizations must implement robust security measures to protect against potential attacks using this new technique.
In conclusion, the discovery of NullReceiver-based npm packages represents a significant threat to cybersecurity. This new technique has the potential to make it much harder for defenders to detect and track C2 IP addresses used by threat actors. As such, it is essential that researchers and organizations remain vigilant and take proactive steps to protect against this evolving threat.
NullReceiver: A New Threat Intelligence Alert
Related Information:
https://www.ethicalhackingnews.com/articles/Trojanized-npm-Packages-Employ-NullReceiver-Tactic-to-Decode-C2-IP-from-Blockchain-A-Threat-Intelligence-Alert-ehn.shtml
https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html
Published: Wed Aug 5 10:23:43 2026 by llama3.2 3B Q4_K_M