Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
public/fonts/fa-solid-400.woff2, not a font. Plaintext JavaScript with a .woff2 extension. This is the NullReceiver loader.
The wallet address matches one documented by researchers at OpenSourceMalware, who named the technique NullReceiver and attributed the activity they examined to the DPRK-linked Contagious Interview campaign, associated with the Lazarus group.
Analysts at OpenSource Malware identified the activity and named the technique NullReceiver. ... NullReceiver works by reading the recipient address from the latest outgoing transaction of an attacker-controlled Ethereum wallet.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
PolinRider is supply-chain campaign that hides obfuscated JavaScript inside compromised developers' .vscode/tasks.json files, fake .woff2 fonts, and legitimate config files like tailwind.config.js, postcss.config.mjs, eslint.config.mjs, App.js and babel.config.cjs.
PolinRider is supply-chain campaign that hides obfuscated JavaScript inside compromised developers' .vscode/tasks.json files, fake .woff2 fonts, and legitimate config files
public/fonts/fa-solid-400.woff2, not a font. Plaintext JavaScript with a .woff2 extension.
C2 URI paths (against attacker-resolved IP) http://<resolved-ip>:443/0x/cls http://<resolved-ip>:443/0x/ls
The malware can retrieve new instructions from a public blockchain that cannot easily be taken down or altered by defenders.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript loader used in the PolinRider campaign, including blockchain-based C2 behavior via Ethereum RPC endpoints and payload delivery/persistence through disguised files and config-file injection.
Mentioned alongside PolinRider in the referenced post, suggesting material connection to the same campaign or tooling.
A Node.js malware loader embedded in malicious npm packages that queries an attacker-controlled Ethereum wallet, decodes command-and-control addresses from blockchain transaction data, and retrieves additional payload stages from resolved infrastructure.
Malware/C2-hiding technique used in trojanized npm packages that retrieves its command-and-control server by decoding an Ethereum transaction recipient address from an attacker-controlled wallet, allowing blockchain-based stealthy C2 resolution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.