NullReceiver's Blank Crypto Transfers Solves the Challenges of EtherHiding
2026-08-02 • Open Source Malware •
https://opensourcemalware.com/blog/nullreceiver-dprk-c2-technique
DPRK-linked Contagious Interview operators embedded NullReceiver in the trojanized npm packages bianira-ui and fluid-type-ui. The technique retrieves an attacker's latest zero-value, zero-data Ethereum transaction and decodes a C2 IP address from the recipient address itself. Unlike EtherHiding, it requires no smart contract, fixed burn address, or calldata, reducing the transaction features defenders can fingerprint. Static analysis identified the wallet used for blockchain lookups and decoded the active C2 address as 166.88.134.62.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| WALLET | 0xa658863ea658863e68656c6c6f697… | 2026-08-02 | 2026-08-02 |
| WALLET | 0xa322e5f3d311d3080e6f0121063e9… | 2026-08-02 | 2026-08-02 |
| IPv4 | 166.88.134.62 | 2026-07-28 | 2026-08-02 |
Related Actors
Related Reports
Shares tags: ContagiousInterview, EtherHiding • Published within a week
Shares tag: ContagiousInterview • Same author: Open Source Malware • Published within a month
Shares tags: NPM, ContagiousInterview • Same author: Open Source Malware
Shares tags: NPM, ContagiousInterview • Same author: Open Source Malware
Shares tags: NPM, ContagiousInterview • Same author: Open Source Malware
2026-05-14 •
60% Match
#NPM
#ContagiousInterview
#BeaverTail
#InvisibleFerret
#Lazarus
#VSCode
#Axios
#TasksJacker
Shares tags: NPM, ContagiousInterview • Same author: Open Source Malware