#NullReceiver

Malware/Tool

2026-08-02 • NullReceiver's Blank Crypto Transfers Solves the Challenges of EtherHiding

NullReceiver is a blockchain-based command-and-control resolution technique embedded in trojanized npm packages, not a standalone malware family. Malicious clones of legitimate Tailwind CSS plugins inspected zero-value, zero-data Ethereum transfers and decoded a command-and-control IP address from bytes in the recipient address. The packages then retrieved additional JavaScript payloads. Researchers linked this tradecraft to DPRK-associated Contagious Interview activity and designed the technique to avoid the data-storage limitations and conspicuous smart-contract artifacts associated with earlier EtherHiding methods.

Tagged Reports

« Back