HackerFeeds

CyberSecurity News

Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

The Hacker News
· August 5, 2026

AI summary

Cybersecurity researchers have discovered an updated version of the EtherHiding technique, which hides command-and-control server IP addresses within fake Ethereum transfer recipient addresses. This new approach, called NullReceiver, involves using empty Ethereum transfers to conceal the IP address. The technique has been observed in two compromised npm packages, bianira-ui and fluid-type-ui. These packages have been trojanized, allowing attackers to use the NullReceiver method to decode the C2 IP address from Ethereum recipient addresses. The evolution of this technique highlights the continued use of blockchain-based methods for command-and-control communication. The NullReceiver approach is a notable development in the EtherHiding technique.

Read the full article at The Hacker Newsthehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.