Researchers have discovered a new npm malware technique linked to the DPRK that conceals command-and-control (C2) infrastructure within generic Ethereum transactions This article explores nullreceiver malicious plugins. . Dubbed NullReceiver, The malicious plugins were present in two trojanized npm packages (bianira-ui@1.27.0 and fluid-type-ui@2.0.8) masquerading as legitimate Tailwind CSS tools.

These packages relate to the DPRK’s Contagious Interview campaign. It removes some of the detection mechanisms used against EtherHiding such as smart-contract interactions, transaction payloads and fixed destination addresses. This method is noteworthy as it stands out from conventional blockchain-malware detection, which typically targets suspicious smart-contract calls, non-empty calldata, or interactions with known crypto addresses. NullReceiver Conceals Ethereum C2 (Source: opensourcemalware) This is an interesting approach, as traditional malware detection is mainly focused on the analysis of suspicious smart contract calls, non-null calldata or interactions with certain cryptocurrency addresses.

Google Threat Intelligence has linked EtherHiding to DPRK-related activity in 2025. EtherHiding hides C2 data in the calldata of transactions sent to the common Ethereum burn address, usually 0x000…dEaD. NullReceiver uses hidden recipient addresses that initially look nonsensical, until an analyst identifies the attacker’s wallet address and decodes the decoding algorithm used by NullReceiver.

Indicators of Compromise IOC Type Indicator Notes Bad npm package bianira-ui@1.27.0 DPRK Contagious Interview campaign cloned Trojanized Tailwind CSS plugin linked to malicious Tailwind CSS plugin. ANY.RUN helps organizations to close blind spots in SOC investigations, contain threats earlier and minimize response costs and business disruption.