Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

Summary

Cybersecurity researchers have identified a new evolution of the EtherHiding technique, which conceals command-and-control (C2) server IP addresses within fabricated Ethereum transaction recipient addresses. This new method, dubbed NullReceiver, was observed in two trojanized npm packages, "bianira-ui" and "fluid-type-ui."

IFF Assessment

FOE

This technique allows attackers to hide their C2 infrastructure within seemingly legitimate blockchain transactions, making it harder for defenders to track and disrupt malicious activity.

Defender Context

Defenders should be aware of this evolving C2 obfuscation technique that leverages blockchain transactions. Monitoring network traffic for unusual Ethereum transactions, especially those involving suspicious or newly discovered npm packages, can help in detecting this threat.

Read Full Story →