logo

NullReceiver's Blank Crypto Transfers Solves the Challenges of EtherHiding

ID: 170437b0-402d-50fb-9feb-dd52400fc9e5

STIX ID: report--170437b0-402d-50fb-9feb-dd52400fc9e5

Feed Name: OpenSourceMalware Blog

Threat Score
85/100

Date Published: 2026-08-02

Date Updated: 2026-08-01

Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2

...
...

NullReceiver is a newly identified DPRK-linked blockchain-based command-and-control technique embedded in two trojanized npm packages ([email protected] and [email protected]). Instead of embedding C2 data in transaction calldata, the malware decodes a C2 IP from the bytes of the recipient address of a zero-value, zero-data Ethereum transfer, making the channel cheaper and harder to detect; the report includes static-analysis findings and IOCs (attacker wallet 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a, encoded recipient 0xa658863ea658863e68656c6c6f6970626f742121, and C2 166.88.134.62:80/443).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.