Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.

The new dead drop resolver approach, observed in two trojanized npm package « bianira-ui » and « fluid-type-ui, » has been codenamed NullReceiver by