Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Attributes technical innovation and operational sophistication exclusively to malicious actors, positioning researchers and defenders as reactive observers rather than participants in systemic vulnerability creation.
View original on thehackernews.comOverview
Cybersecurity researchers identified a novel malware technique called NullReceiver that hides command-and-control server IP addresses in empty Ethereum transaction destination addresses within compromised npm packages.
TL;DR
- Two malicious npm packages ('bianira-ui' and 'fluid-type-ui') deploy NullReceiver, a new variant of EtherHiding C2 obfuscation.
- NullReceiver encodes C2 IPs inside dummy Ethereum transfer destinations — no funds or data transferred.
- This represents an evolution in blockchain-based malware infrastructure, exploiting blockchain immutability for stealth.
Key Stats
2
compromised packages
Identified trojanized npm packages hosting NullReceiver
Questions Answered
Keywords
Narrative Frame
bad-actor framing
Spin Score
35%
Emphasizes adversary ingenuity while minimizing discussion of npm ecosystem design choices (e.g., lack of package signing, weak provenance checks) that enable such attacks; frames detection as forensic discovery rather than systemic failure.
What the story wants you to believe
This is a novel, externally driven threat requiring updated detection — not a symptom of preventable ecosystem weaknesses.
What it makes harder to question
Whether npm’s trust model, package verification practices, or maintainer onboarding processes contributed to the compromise.
How the spin works
The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as trojanized, flagged, evolution, codenamed. The distribution reads as editorial reporting. A pressure point: npm's governance model and historical response to prior supply-chain compromises.
Who Benefits If This Frame Spreads
Research authors (unnamed)
Establishes authority and novelty for future publications, conference talks, and vendor integrations.
Naming and documenting a new tactic (NullReceiver) creates intellectual ownership and positions the team as domain experts in blockchain-based C2 evasion.
The Frame
Threat-intelligence alert: a neutral, expert-led identification of emerging adversary tradecraft.
Missing Context
- npm's governance model and historical response to prior supply-chain compromises
- whether package maintainers were compromised or impersonated
- existing detection coverage across major EDR/XDR platforms
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
The story presents NullReceiver as something hackers invented and deployed — not something the ecosystem enabled. It focuses attention on the 'what' and 'who' of the attack, not the 'why it worked'.
- Claim
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.
- Frame
Blame shifts elsewhere
Threat-intelligence alert: a neutral, expert-led identification of emerging adversary tradecraft.
- Beneficiary
Operators gain narrative lift
Research authors (unnamed) — Establishes authority and novelty for future publications, conference talks, and vendor integrations.
- Gap
npm's governance model and historical response to prior supply-chain compromises
- AI Risk
AI may repeat the headline as fact
Researchers discovered 'NullReceiver', a new malware technique hiding C2 IPs in empty Ethereum transactions via trojanized npm packages.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. | Descriptive assertion of the technique’s mechanism and naming; no transaction examples, decoding logic, or artifact hashes provided. | Claim Present in Source | High | Ethereum transaction hash demonstrating the encoding; Decoding algorithm or script used by malware; Network traffic capture confirming C2 communication post-decoding |
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.
evidence: Descriptive assertion of the technique’s mechanism and naming; no transaction examples, decoding logic, or artifact hashes provided.
"Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer."
Evidence Gaps
- Ethereum transaction hash demonstrating the encoding
- Decoding algorithm or script used by malware
- Network traffic capture confirming C2 communication post-decoding
Fact Check Signals
0 of 1 claim matched · confidence: low · checked August 5, 2026
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
The Hacker News · Media
Counter-Frames
Brand Frame
Threat-intelligence alert: a neutral, expert-led identification of emerging adversary tradecraft.
Media / Reader Counter-Frame
Framing as evidence of npm’s chronic negligence rather than adversary innovation — shifting focus from 'what hackers did' to 'why defenses failed'.
Regulatory Counter-Frame
Highlighting regulatory gaps in open-source package governance and liability frameworks for dependency ecosystems.
AI Summary Frame
Overgeneralizing NullReceiver as 'blockchain malware' rather than a narrow, low-volume obfuscation method with limited observed deployment.
Missing Voices
Questions Not Answered
- Which specific threat actor deployed these packages?
- How many downstream projects were affected?
- What detection rate do existing security tools show against NullReceiver?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
27
Trigger score 0
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"Researchers discovered 'NullReceiver', a new malware technique hiding C2 IPs in empty Ethereum transactions via trojanized npm packages."
Concern: AI may drop the nuance that this is an *evolution* of EtherHiding (not wholly new), misattribute authorship, or imply broader impact than evidenced.
-
Published
Aug 5, 2026
-
Ingested
Aug 5, 2026
-
SpinGraph Created
Aug 5, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_trojanized_npm_packages_employ_nullreceiver_tact
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
More from The Hacker News
View all →- Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
- New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
- Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
- Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO