Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Read full story on The Hacker News
Share
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
AI disclosure

Summary

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by

Original reporting

Open original source
Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.