Scworld North Korea's NullReceiver C2 Technique Enhances Stealth in Cyber Attacks
Article Content
- •NullReceiver is a new C2 technique from North Korea that hides IP addresses in Ethereum transactions.
- •Two trojanized npm packages, bianira-ui and fluid-type-ui, implement this stealthy method.
- •The technique improves upon EtherHiding by eliminating fixed destination addresses, complicating attribution.
North Korean threat actors have introduced a new command-and-control (C2) technique named NullReceiver, which conceals the C2 server's IP address within empty Ethereum transactions. This method, an evolution of EtherHiding, was found in two trojanized npm packages, bianira-ui and fluid-type-ui, which mimic Tailwind CSS plugins. The technique allows malware to decode the IP address from the recipient address of a zero-value Ethereum transfer, making detection and attribution more difficult. While the packages have been downloaded a few hundred times, the method's stealthiness and reduced cost make it a significant advancement in C2 strategies. NullReceiver limits the data encoded to just a few bytes, enhancing its resilience against detection. The attack primarily affects users of the compromised npm packages, raising concerns over supply chain security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track NullReceiver and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Supply Chain Attack: GHAPPIER Loader Exploits npm Trusted Publishing On September 9, 2026, an attacker compromised the maintainer account of the npm package @dforge-core/dforge-mcp for 105 minutes, releasing a malicious loader named GHAPPIER. The attack involved two versions: 0.2.20, which failed to install, and 0.2.21, which successfully shipped the loader. The malicious release…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…