Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The wallet address matches one documented by researchers at OpenSourceMalware, who named the technique NullReceiver and attributed the activity they examined to the DPRK-linked Contagious Interview campaign, associated with the Lazarus group.
Analysts at OpenSource Malware identified the activity and named the technique NullReceiver. ... NullReceiver works by reading the recipient address from the latest outgoing transaction of an attacker-controlled Ethereum wallet.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The technique was found in two malicious npm packages, bianira-ui version 1.27.0 and fluid-type-ui version 2.0.8. Both packages impersonated legitimate Tailwind CSS plugins, creating a supply-chain risk for developers who install dependencies without closely reviewing their source.
The affected packages use Node.js code to query public Ethereum remote procedure call services, examine the attacker wallet’s latest transfer, decode the recipient address, and contact the resulting server. | The method places a command server address inside an empty Ethereum transaction, making the activity look like a normal crypto transfer rather than a malware signal.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Node.js malware loader embedded in malicious npm packages that queries an attacker-controlled Ethereum wallet, decodes command-and-control addresses from blockchain transaction data, and retrieves additional payload stages from resolved infrastructure.
Malware/C2-hiding technique used in trojanized npm packages that retrieves its command-and-control server by decoding an Ethereum transaction recipient address from an attacker-controlled wallet, allowing blockchain-based stealthy C2 resolution.
A malware C2-resolution technique used by trojanized npm packages that queries Ethereum RPC services, reads the recipient address from an attacker-controlled wallet’s latest outgoing transaction, decodes bytes from that address into a C2 IP, and then contacts the resulting command-and-control server. It is designed to hide and rotate malware infrastructure via normal-looking blockchain transactions.
NullReceiver is presented as a named malware/C2 technique associated with blank crypto transfers and EtherHiding-style command-and-control evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.