CuraSec

Act active

Trojanized npm Packages Use Blockchain to Hide C2 IP (NullReceiver)

2026-08-06 13:03 UTC · The Hacker News · read the source ↗ #npm-supply-chain#c2-evasion#blockchain
  • Engineer — Act: Two named malicious packages — ‘bianira-ui’ and ‘fluid-type-ui’ — are trojanized with active C2 capability; audit all dependency trees and lock files for these packages and remove them immediately if found.
  • SOC/IR — Plan: NullReceiver is a novel dead-drop resolver technique that hides C2 IPs inside empty Ethereum transfer destinations, making traditional blocklist-based detections ineffective; build or tune detections for unusual outbound Ethereum RPC calls originating from build pipelines or developer endpoints this quarter.
  • Leader — Learn: Attackers are using blockchain infrastructure to evade C2 detection in software supply-chain attacks — a technique evolution worth including in risk-posture discussions, but no immediate leadership action is required given the limited scope and absence of a major corroborated campaign.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.