News Room
16
Share
Trojanized npm Packages Deploy 'NullReceiver' Tactic to Obfuscate C2 via Ethereum Blockchain
highCyber Espionage

Trojanized npm Packages Deploy 'NullReceiver' Tactic to Obfuscate C2 via Ethereum Blockchain

Intelligence analysts have identified a sophisticated evolution of the EtherHiding technique, dubbed 'NullReceiver,' where APT actors use trojanized npm packages to decode C2 IPs from empty Ethereum transactions.

11 August 2026Last updated 18 August 20265 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
High
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
Source:
Mandiant
Read Time:
5 min

Executive Summary

In a significant escalation of supply chain tradecraft, cybersecurity researchers have uncovered a new cyber espionage campaign utilizing trojanized npm packages to deliver stealthy backdoors. The campaign, identified in early August 2026, leverages a novel technique named 'NullReceiver.' This method represents an evolution of the 'EtherHiding' tactic, where threat actors utilize the Ethereum blockchain to host and obfuscate command-and-control (C2) infrastructure. By embedding malicious logic within widely used JavaScript libraries, the attackers have successfully infiltrated development environments across the technology and financial sectors, aiming to establish long-term persistence and facilitate data exfiltration.

Threat Analysis

The 'NullReceiver' campaign is characterized by its high degree of operational security and its focus on the software supply chain. By targeting the npm registry, the actors exploit the inherent trust in open-source ecosystems. The primary objective appears to be the compromise of high-value workstations belonging to software engineers and DevOps professionals. Once a package is integrated into a local environment or a CI/CD pipeline, the malware executes a multi-stage infection chain designed to bypass traditional EDR (Endpoint Detection and Response) solutions. The use of blockchain-based C2 makes the infrastructure highly resilient to takedowns, as the malicious instructions are permanently recorded on a decentralized ledger.

Technical Details

The technical core of the 'NullReceiver' tactic involves the manipulation of Ethereum transaction data. Unlike previous iterations that stored C2 IPs in smart contract code or transaction input data, NullReceiver decodes the C2 server IP address from the 'To' address of a series of empty (zero-value) Ethereum transfers.

  1. Initial Access: The attacker publishes a legitimate-looking npm package that performs its advertised function but contains a hidden post-install script.
  2. Blockchain Query: Upon execution, the script queries a public Ethereum gateway (such as Infura or Etherscan) for the latest transactions associated with a specific 'vanity' wallet address controlled by the actor.
  3. Decoding: The malware extracts the destination addresses of these transactions. These addresses are not random; they are mathematically crafted so that, when concatenated and passed through a specific XOR cipher, they reveal the current IP address and port of the C2 server.
  4. Payload Delivery: Once the C2 is reached, the malware downloads a second-stage RAT (Remote Access Trojan) capable of screen capture, keystroke logging, and file exfiltration.

Attribution Assessment

While definitive attribution remains ongoing, the technical sophistication and infrastructure overlap suggest the involvement of a PRC-aligned threat actor, potentially a subgroup of 'Salt Typhoon' or 'APT41.' The focus on telecommunications and technology sectors, combined with the use of advanced obfuscation techniques to maintain long-term access, aligns with known Chinese state-sponsored espionage objectives. However, the adoption of blockchain-based C2 is also a hallmark of certain North Korean (Lazarus Group) operations, leading to a moderate confidence assessment that this is a nation-state-backed entity focused on strategic intelligence gathering.

Implications

The emergence of NullReceiver highlights the growing vulnerability of the global software supply chain. As organizations increasingly rely on automated dependency management, the risk of 'poisoned' packages becomes a systemic threat. Furthermore, the use of decentralized infrastructure for C2 communication presents a significant challenge for network defenders, as blocking individual IP addresses is ineffective when the source of truth resides on a public blockchain. This campaign signals a shift toward more resilient, 'un-stoppable' malware architectures.

Recommendations

Encrygma recommends the following immediate actions for all partner organizations:

  • Dependency Auditing: Implement strict version pinning and use tools like npm audit or Snyk to scan for known malicious packages.
  • Network Filtering: Monitor and restrict outbound traffic to public blockchain gateways (e.g., Infura, Alchemy) from development environments unless strictly necessary.
  • Behavioral Monitoring: Deploy EDR solutions configured to alert on unusual post-install script behavior, such as unexpected network connections or the spawning of shell processes from package managers.
  • Zero Trust Architecture: Enforce the principle of least privilege for developer workstations to limit the potential impact of a local compromise.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo