New Trojan Technique Uses Blockchain for IP Obfuscation
Cybersecurity researchers have discovered a new technique being used in two compromised npm packages. This technique, known as NullReceiver, employs an innovative method for obfuscating Command-and-Control (C2) server IP addresses. The affected packages, bianira-ui and fluid-type-ui, utilize a blockchain-based strategy to conceal the IP addresses. The NullReceiver technique is an evolution of the already known EtherHiding method. In this new strategy, the IP address of the C2 server is hidden within a fictitious target address inside an empty Ethereum transaction.
This approach significantly complicates the identification and blocking of C2 servers. Researchers have found that the Trojan packages are capable of dynamically decrypting the IP address, meaning that attackers can quickly adapt their infrastructure. This flexibility allows cybercriminals to obscure their activities and evade detection by security solutions. The discovery of the NullReceiver technique is part of a larger trend where attackers leverage blockchain technologies to disguise their operations. This development indicates that cybercrime is becoming increasingly complex, and traditional security measures may not be sufficient to detect such threats.
The affected npm packages have been used in various projects, increasing the spread of the malware. Developers who have integrated these packages into their applications are potentially at risk, as the Trojans operate in the background, stealing data or compromising systems. Security researchers recommend that developers and companies regularly review their dependencies and ensure they only use trusted packages. Utilizing tools for monitoring and analyzing code dependencies can help detect such threats early. The discovery of the NullReceiver technique underscores the need for continuous updates and adjustments to security practices.
Given the ever-evolving threat landscape, it is crucial for companies to take proactive measures to protect their systems. Researchers have already reported the new Trojan packages to the relevant security authorities. The exact number of affected systems is currently unknown; however, it is estimated that the spread of these packages has significantly increased in recent months. The vulnerability could potentially affect thousands of developers and companies.
Security research will continue to be pursued intensively to better understand the impacts of the NullReceiver technique. Researchers are working on developing countermeasures to halt the spread of such Trojans and enhance the security of software development. The discovery was published on August 5, 2026, and the security community is urged to remain vigilant and keep up with the latest developments in cybersecurity.
💬 Comments (0)
No comments yet. Be the first to comment!