Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses — Ravie LakshmananAug 05, 2026Cyber Espionage / Threat Intelligence [https://blogger.
What’s new: Researchers have identified a new technique called NullReceiver, used in two trojanized npm packages, “bianira-ui” and “fluid-type-ui,” which decodes command-and-control (C2) IP addresses from Ethereum recipient addresses. This method, linked to North Korean threat actors, improves upon the previous EtherHiding technique by embedding the C2 IP directly in the bytes of a zero-value Ethereum transfer, making detection more challenging. The affected packages have been downloaded a few hundred times since their release on July 28, 2026, but are no longer available for download.
Who’s affected
Developers and organizations using the compromised npm packages “bianira-ui” and “fluid-type-ui” may be at risk of malware deployment due to the embedded C2 communication mechanism.
What to do
- Audit your npm package dependencies and remove any instances of “bianira-ui” and “fluid-type-ui.”
- Monitor network traffic for unusual connections to unknown IP addresses.
- Implement security measures to detect and block unauthorized outbound connections.
- Stay updated on threat intelligence regarding North Korean cyber activities and similar tactics.



