<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Npm-Supply-Chain on CuraSec</title><link>https://curasec.metacog.co.kr/tags/npm-supply-chain/</link><description>Recent content in Npm-Supply-Chain on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 06 Aug 2026 13:03:19 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/npm-supply-chain/index.xml" rel="self" type="application/rss+xml"/><item><title>Trojanized npm Packages Use Blockchain to Hide C2 IP (NullReceiver)</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-trojanized-npm-packages-employ-nullreceiver-tactic-to-decode/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-trojanized-npm-packages-employ-nullreceiver-tactic-to-decode/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Two named malicious packages — &amp;lsquo;bianira-ui&amp;rsquo; and &amp;lsquo;fluid-type-ui&amp;rsquo; — are trojanized with active C2 capability; audit all dependency trees and lock files for these packages and remove them immediately if found.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> NullReceiver is a novel dead-drop resolver technique that hides C2 IPs inside empty Ethereum transfer destinations, making traditional blocklist-based detections ineffective; build or tune detections for unusual outbound Ethereum RPC calls originating from build pipelines or developer endpoints this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Attackers are using blockchain infrastructure to evade C2 detection in software supply-chain attacks — a technique evolution worth including in risk-posture discussions, but no immediate leadership action is required given the limited scope and absence of a major corroborated campaign.&lt;/li>
&lt;/ul></description></item></channel></rss>