Executive Summary
In August 2026, cybersecurity researchers identified a sophisticated supply chain attack involving two trojanized npm packages, 'bianira-ui' and 'fluid-type-ui'. These packages employed a novel technique, dubbed 'NullReceiver', to conceal command-and-control (C2) server IP addresses within the recipient addresses of zero-value Ethereum transactions. This method, an evolution of the previously documented 'EtherHiding' technique, was linked to North Korean state-sponsored actors. The malicious packages were uploaded to npm on July 28, 2026, and collectively downloaded nearly 700 times before their removal. The 'NullReceiver' approach enhances operational resilience by eliminating fixed, trackable destinations, thereby complicating detection and mitigation efforts. This incident underscores the escalating sophistication of supply chain attacks and the persistent threat posed by nation-state actors leveraging blockchain technologies for stealthy malware deployment.
Why This Matters Now
The 'NullReceiver' technique represents a significant advancement in cyberattack methodologies, leveraging blockchain's inherent properties to evade detection. As supply chain attacks become more sophisticated, organizations must enhance their security measures to protect against such innovative threats.
Attack Path Analysis
Attackers compromised the software supply chain by publishing trojanized npm packages, leading to the execution of malicious code upon installation. The malware decoded a command-and-control (C2) IP address from Ethereum transaction data, establishing a covert communication channel. This allowed attackers to execute commands and potentially exfiltrate sensitive data from infected systems.
Kill Chain Progression
Initial Compromise
Description
Attackers published malicious npm packages ('bianira-ui' and 'fluid-type-ui') that, when installed, executed code to retrieve a C2 IP address embedded in Ethereum transaction data.
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Dependencies and Development Tools
Application Layer Protocol: Web Protocols
Data Obfuscation: Protocol Impersonation
User Execution: Malicious File
Ingress Tool Transfer
Dynamic Resolution: Domain Generation Algorithms
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that software applications are developed securely
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Regularly test and monitor systems
Control ID: 500.14(b)
DORA – ICT risk management framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity risk management measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Supply chain attacks targeting npm packages pose severe risks to software development workflows, requiring enhanced egress security and zero trust segmentation for development environments.
Information Technology/IT
IT infrastructure faces compromise through trojanized packages and blockchain-based C2 communication, necessitating multicloud visibility controls and threat detection capabilities for client protection.
Financial Services
North Korean threat actors targeting financial institutions through sophisticated EtherHiding variants require encrypted traffic monitoring and anomaly detection to prevent cryptocurrency-based command control operations.
Computer/Network Security
Cybersecurity firms must adapt defenses against NullReceiver techniques using inline IPS and cloud native security fabric solutions to detect blockchain-concealed malware communications.
Sources
- Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresseshttps://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.htmlVerified
- North Korean threat actors turn blockchains into malware delivery servershttps://www.csoonline.com/article/4074916/north-korean-threat-actors-turn-blockchains-into-malware-delivery-servers.htmlVerified
- North Korean state-sponsored hackers slip unremovable malware inside blockchains to steal cryptocurrencyhttps://www.tomshardware.com/tech-industry/cyber-security/north-korea-hiding-malware-inside-blockchain-smart-contractsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely limit the execution of unauthorized code by enforcing strict workload isolation and identity-based policies.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the malware's ability to escalate privileges by enforcing least-privilege access controls and segmenting workloads.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit lateral movement by enforcing strict segmentation and monitoring east-west traffic patterns.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the establishment of covert C2 channels by providing comprehensive monitoring and control over network communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit data exfiltration by enforcing strict egress policies and monitoring outbound traffic.
The CNSF would likely limit the overall impact of the compromise by enforcing strict segmentation and access controls, thereby reducing the blast radius of the attack.
Impact at a Glance
Affected Business Functions
- Software Development
- Supply Chain Management
- IT Security
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of sensitive source code and intellectual property due to compromised npm packages.
Recommended Actions
Key Takeaways & Next Steps
- • Implement supply chain security measures to vet and monitor third-party software components.
- • Deploy Cloud Native Security Fabric (CNSF) to enforce real-time inspection and policy enforcement across workloads.
- • Utilize Zero Trust Segmentation to limit lateral movement by enforcing least privilege access controls.
- • Establish Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.



