
Trojanized npm Packages Employ 'NullReceiver' Tactic to Conceal C2 Infrastructure via Blockchain
Researchers have identified a sophisticated evolution of the EtherHiding technique, dubbed 'NullReceiver,' which leverages empty Ethereum transfers to mask command-and-control (C2) IP addresses.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- The Hacker News
- Read Time:
- 5 min
Executive Summary
On August 5, 2026, cybersecurity researchers identified a significant evolution in blockchain-based command-and-control (C2) techniques. The new method, termed 'NullReceiver,' represents a sophisticated advancement of the 'EtherHiding' tactic. By embedding C2 server IP addresses within the destination fields of empty Ethereum transactions, threat actors are successfully bypassing traditional traffic analysis tools. This development coincides with a broader surge in state-sponsored espionage operations targeting critical infrastructure and software supply chains.
Threat Analysis
The use of blockchain for C2 is not new, but the NullReceiver tactic adds a layer of obfuscation that makes detection nearly impossible for standard EDR and NDR solutions. Unlike previous iterations that stored data in transaction logs or smart contracts, NullReceiver utilizes the 'to' address field of a zero-value transfer. This makes the traffic appear as legitimate, albeit failed or empty, blockchain activity. This technique is being integrated into trojanized npm packages, targeting developers who may inadvertently pull these dependencies into sensitive corporate or government environments.
Technical Details
The infection begins with the distribution of trojanized npm packages. Once executed, the malware initiates a query to the Ethereum blockchain. It specifically looks for transactions associated with a pre-defined 'sender' wallet controlled by the adversary. The malware then extracts the 'receiver' address from a transaction that has a value of zero. This 40-character hexadecimal address is not a valid destination but is actually an encoded IP address and port configuration. By decoding this string, the malware identifies its primary C2 server. This 'dead drop' mechanism ensures that even if the primary C2 is taken down, the actors can update the blockchain with a new address, maintaining persistence without needing to update the malware code itself.
Attribution Assessment
While no specific group has claimed responsibility, the complexity of the NullReceiver tactic aligns with the tradecraft of advanced persistent threats (APTs) previously linked to East Asian interests. Similar 'conflict-informed espionage' patterns have been observed by ESET and Mandiant, where technical innovations are deployed to fill specific intelligence gaps. The focus on npm supply chains mirrors recent activities by clusters such as 'DeceptiveDevelopment' (DPRK) and 'OP-512' (China), both of which have demonstrated a high degree of proficiency in targeting developer environments to gain initial access to high-value networks.
Implications
The shift toward blockchain-based C2 infrastructure signals a move away from traditional domain-based or IP-based infrastructure that can be easily blacklisted. For intelligence agencies and corporate security teams, this necessitates a shift in monitoring strategies. If state-sponsored actors can hide their communications within the noise of public ledgers, the 'dwell time' of an intrusion could increase significantly. Furthermore, the targeting of the npm ecosystem continues to be a primary vector for large-scale espionage, as a single compromised package can provide access to thousands of downstream organizations.
Recommendations
Organizations are advised to implement strict software composition analysis (SCA) to vet all third-party dependencies. Security teams should monitor for unusual outbound traffic to known blockchain gateways (e.g., Infura, Etherscan) from non-developer workstations. Additionally, implementing 'zero-trust' principles at the network level—restricting outbound connections to only verified, necessary services—can mitigate the risk of unauthorized C2 communication, even when hidden via blockchain protocols.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Iranian-Linked 'Nimbus Manticore' Expands Espionage Arsenal with Advanced Backdoors

Iranian 'Nimbus Manticore' APT Escalates Global Espionage via Sophisticated Coding Test Phishing

