Researchers identified a new blockchain-based command-and-control resolution technique dubbed NullReceiver in two trojanized npm packages, bianira-ui@1.27.0 and fluid-type-ui@2.0.8, tied to the DPRK-linked Contagious Interview campaign. The packages use a hardcoded Ethereum wallet, 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a, and recover their next-stage infrastructure by querying the wallet’s latest zero-value, zero-data Ethereum transaction rather than relying on embedded domains or traditional blockchain-stored payloads.
Analysis showed the malware decodes the command-and-control IP directly from the recipient address of that blank transaction, yielding 166.88.134.62, with ports 443 and 80 identified as associated infrastructure. Researchers said the approach improves on EtherHiding by avoiding smart contracts, calldata, and fixed public sink addresses, making the C2 lookup harder to spot while leaving only minimal on-chain artifacts; the findings were derived from static analysis of the published npm tarballs and review of public blockchain activity without executing the packages.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
OpenSourceMalware reported identifying a new blockchain-based C2 resolution technique called NullReceiver in the trojanized npm packages bianira-ui@1.27.0 and fluid-type-ui@2.0.8, attributing the activity to the DPRK-linked Contagious Interview campaign. Their analysis recovered infrastructure including 166.88.134.62 on ports 443 and 80 from the attacker’s Ethereum transaction pattern.
The OpenSourceMalware article states that Google Threat Intelligence linked the EtherHiding blockchain-based command-and-control technique to a DPRK-linked actor in October 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyberaccord.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcebsky.app
Open sourceopensourcemalware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.