---
title: "Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain | SpinGraph: Bad-actor framing"
description: "SpinGraph analysis of The Hacker News's Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain story: bad-actor framing, The Shield…"
	canonical: "https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain"
html: "https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain"
json: "https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain.json"
markdown: "https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain.md"
keywords: ["NullReceiver", "EtherHiding", "npm supply chain", "The Shield", "narrative intelligence"]
date: "2026-08-05T13:41:27+00:00"
modified: "2026-08-05T19:36:14.111212+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Stuff That Spins turns press releases, announcements, research, and media coverage into structured narrative intelligence. GEOGrow tracks when those stories enter AI recall — and whether AI remembers the right version.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain#article","headline":"Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain","alternativeHeadline":"Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain | SpinGraph: Bad-actor framing","description":"SpinGraph analysis of The Hacker News's Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain story: bad-actor framing, The Shield…","datePublished":"2026-08-05T13:41:27+00:00","dateModified":"2026-08-05T19:36:14.111212+00:00","url":"https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","keywords":"NullReceiver, EtherHiding, npm supply chain, blockchain C2","author":{"@type":"Organization","name":"The Hacker News","url":"https://feeds.feedburner.com/TheHackersNews"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html","about":[{"@type":"Thing","name":"NullReceiver"},{"@type":"Thing","name":"EtherHiding"},{"@type":"Thing","name":"npm supply chain"},{"@type":"Thing","name":"blockchain C2"}],"mentions":[{"@type":"Organization","name":"The Hacker News"}],"abstract":"Two malicious npm packages ('bianira-ui' and 'fluid-type-ui') deploy NullReceiver, a new variant of EtherHiding C2 obfuscation. NullReceiver encodes C2 IPs inside dummy Ethereum transfer destinations — no funds or data transferred. This represents an evolution in blockchain-based malware infrastructure, exploiting blockchain immutability for stealth."},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain","item":"https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain#spin-analysis","headline":"Spin Analysis: bad-actor framing","description":"Emphasizes adversary ingenuity while minimizing discussion of npm ecosystem design choices (e.g., lack of package signing, weak provenance checks) that enable such attacks; frames detection as forensic discovery rather than systemic failure.","about":{"@type":"DefinedTerm","name":"bad-actor framing","description":"Threat-intelligence alert: a neutral, expert-led identification of emerging adversary tradecraft.","termCode":"The Shield"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":35,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"moderate"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"Researchers discovered 'NullReceiver', a new malware technique hiding C2 IPs in empty Ethereum transactions via trojanized npm packages."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Threat-intelligence alert: a neutral, expert-led identification of emerging adversary tradecraft."},{"@type":"PropertyValue","name":"Missing Context","value":"npm's governance model and historical response to prior supply-chain compromises; whether package maintainers were compromised or impersonated; existing detection coverage across major EDR/XDR platforms"},{"@type":"PropertyValue","name":"How the Spin Works","value":"The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as trojanized, flagged, evolution, codenamed. The distribution reads as editorial reporting. A pressure point: npm's governance model and historical response to prior supply-chain compromises."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.","appearance":"Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.","author":{"@type":"Organization","name":"The Hacker News"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"compromised packages","value":"2","description":"Identified trojanized npm packages hosting NullReceiver"}]}]}
---

# Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

**Source:** Unknown  
**Published:** August 5, 2026  
**Original:** https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

Cybersecurity researchers identified a novel malware technique called NullReceiver that hides command-and-control server IP addresses in empty Ethereum transaction destination addresses within compromised npm packages.

### TL;DR

- Two malicious npm packages ('bianira-ui' and 'fluid-type-ui') deploy NullReceiver, a new variant of EtherHiding C2 obfuscation.
- NullReceiver encodes C2 IPs inside dummy Ethereum transfer destinations — no funds or data transferred.
- This represents an evolution in blockchain-based malware infrastructure, exploiting blockchain immutability for stealth.

### Key Stats

- **2** — compromised packages. Identified trojanized npm packages hosting NullReceiver

<a id="spingraph"></a>

## SpinGraph

The story presents NullReceiver as something hackers invented and deployed — not something the ecosystem enabled. It focuses attention on the 'what' and 'who' of the attack, not the 'why it worked'.

- **Claim:** Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based
- **Frame:** Blame shifts elsewhere
- **Beneficiary:** Operators gain narrative lift
- **Gap:** npm's governance model and historical response to prior supply-chain compromises
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 35%
- **Evidence Strength:** 75%
- **Narrative Risk:** 75%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** deflect_scrutiny  

### The Spin in Plain English

The story presents NullReceiver as something hackers invented and deployed — not something the ecosystem enabled. It focuses attention on the 'what' and 'who' of the attack, not the 'why it worked'.

**What the story wants you to believe:** This is a novel, externally driven threat requiring updated detection — not a symptom of preventable ecosystem weaknesses.  

**What it makes harder to question:** Whether npm’s trust model, package verification practices, or maintainer onboarding processes contributed to the compromise.  

**How the Spin Works:** The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as trojanized, flagged, evolution, codenamed. The distribution reads as editorial reporting. A pressure point: npm's governance model and historical response to prior supply-chain compromises.  

### Questions This Story Raises

- What question is the story steering away from?
- What evidence would resolve that question?
- Who is not quoted or represented?
- Why does the main frame leave this out: “npm's governance model and historical response to prior supply-chain compromises”?
- Why does the main frame leave this out: “whether package maintainers were compromised or impersonated”?

### Who Benefits If This Frame Spreads

- **Research authors (unnamed)** — Establishes authority and novelty for future publications, conference talks, and vendor integrations. _(Naming and documenting a new tactic (NullReceiver) creates intellectual ownership and positions the team as domain experts in blockchain-based C2 evasion.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** bad-actor framing  
**Category:** The Shield  
**Spin Score:** 35%  

Emphasizes adversary ingenuity while minimizing discussion of npm ecosystem design choices (e.g., lack of package signing, weak provenance checks) that enable such attacks; frames detection as forensic discovery rather than systemic failure.

**Who Benefits If This Frame Spreads:** Cybersecurity research team gains credibility as early detectors of novel TTPs.

**The Frame:** Threat-intelligence alert: a neutral, expert-led identification of emerging adversary tradecraft.

### Missing Context

- npm's governance model and historical response to prior supply-chain compromises
- whether package maintainers were compromised or impersonated
- existing detection coverage across major EDR/XDR platforms

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** trojanized, flagged, evolution, codenamed

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
Article reports observed behavior (empty Ethereum transfers encoding IPs) and names two packages, but provides no code snippets, transaction hashes, or reproducible analysis steps.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** moderate  
If independent analysts fail to reproduce NullReceiver’s decoding mechanism or confirm the packages’ malicious payloads, the novelty claim could be undermined — damaging research credibility without affecting core security implications.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** Researchers discovered 'NullReceiver', a new malware technique hiding C2 IPs in empty Ethereum transactions via trojanized npm packages.  
AI may drop the nuance that this is an *evolution* of EtherHiding (not wholly new), misattribute authorship, or imply broader impact than evidenced.  
**Counter-Frame (Media):** Framing as evidence of npm’s chronic negligence rather than adversary innovation — shifting focus from 'what hackers did' to 'why defenses failed'.  
**Missing Voices:** npm maintainers, package authors of 'bianira-ui' and 'fluid-type-ui', open-source foundation representatives  

### Questions Not Answered

- Which specific threat actor deployed these packages?
- How many downstream projects were affected?
- What detection rate do existing security tools show against NullReceiver?

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.

**Category:** safety  
**Verification:** Claim Present in Source  
**Risk:** high  
**Evidence presented:** Descriptive assertion of the technique’s mechanism and naming; no transaction examples, decoding logic, or artifact hashes provided.  
> Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.

**Evidence Gaps:** Ethereum transaction hash demonstrating the encoding; Decoding algorithm or script used by malware; Network traffic capture confirming C2 communication post-decoding  

<a id="ai-recall"></a>

## AI Recall

- **Published:** August 5, 2026  
- **SpinGraph summary:** Attributes technical innovation and operational sophistication exclusively to malicious actors, positioning researchers and defenders as reactive observers rather than participants in systemic vulnerability creation.  
- **Likely AI summary:** Researchers discovered 'NullReceiver', a new malware technique hiding C2 IPs in empty Ethereum transactions via trojanized npm packages.  

## Citation Summary

This page documents the first public identification and naming of NullReceiver — a novel blockchain-based C2 obfuscation technique in npm supply chain malware — making it a primary reference for threat intelligence analysts tracking EtherHiding variants.

---
*HTML version: https://stuffthatspins.com/spin/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-blockchain*
