Login
← All news

Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

The Hacker News Security

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm package "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by…

Read the full story on The Hacker News https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html
Attacks like this land on ordinary sites far more often than on chosen targets. If you would rather your site never became the story, CrockyHost hosting ships with daily backups, automatic updates and a firewall we manage.