Researchers identified a new blockchain-based command-and-control resolution technique dubbed NullReceiver in two trojanized npm packages, bianira-ui@1.27.0 and fluid-type-ui@2.0.8, tied to the DPRK-linked Contagious Interview campaign. The packages use a hardcoded Ethereum wallet, 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a, and recover their next-stage infrastructure by querying the wallet’s latest zero-value, zero-data Ethereum transaction rather than relying on embedded domains or traditional blockchain-stored payloads.
Analysis showed the malware decodes the command-and-control IP directly from the recipient address of that blank transaction, yielding 166.88.134.62, with ports 443 and 80 identified as associated infrastructure. Researchers said the approach improves on EtherHiding by avoiding smart contracts, calldata, and fixed public sink addresses, making the C2 lookup harder to spot while leaving only minimal on-chain artifacts; the findings were derived from static analysis of the published npm tarballs and review of public blockchain activity without executing the packages.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
On August 10, 2026, Sonatype Research Labs identified six npm packages carrying the same malicious loader that uses Ethereum transactions as a dead-drop to recover command-and-control infrastructure. The set included three hijacked legitimate packages and three malicious packages published to distribute the malware, and Sonatype linked the activity to the DPRK-linked Contagious Interview campaign through a shared Ethereum wallet address.
OpenSourceMalware reported identifying a new blockchain-based C2 resolution technique called NullReceiver in the trojanized npm packages bianira-ui@1.27.0 and fluid-type-ui@2.0.8, attributing the activity to the DPRK-linked Contagious Interview campaign. Their analysis recovered infrastructure including 166.88.134.62 on ports 443 and 80 from the attacker’s Ethereum transaction pattern.
The OpenSourceMalware article states that Google Threat Intelligence linked the EtherHiding blockchain-based command-and-control technique to a DPRK-linked actor in October 2025.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
10 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcemalware.news
Open sourcesonatype.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcebsky.app
Open sourceopensourcemalware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.