Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Trojanized npm Packages Use NullReceiver to Decode C2 IP from Blockchain

Researchers discovered two compromised npm libraries that extract a hidden C2 server IP from a fabricated Ethereum transfer, illustrating a supply‑chain attack that challenges SOC 2 vendor‑management controls.

LiveThreat™ Intelligence · 📅 August 05, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
1 recommended
📰
Source
thehackernews.com

Trojanized npm Packages Use NullReceiver to Decode C2 IP from Blockchain

What Happened — Researchers identified two malicious npm packages, bianira‑ui and fluid‑type‑ui, that embed a “NullReceiver” resolver. The resolver reads a fabricated Ethereum transfer destination, extracts a hidden C2 server IP from the blockchain, and activates the payload on victim machines.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a supply‑chain breach where a third‑party library bypasses traditional perimeter defenses – exactly the scenario SOC 2 vendor‑management controls (CC6.1) are designed to detect and evidence.
  • Continuous monitoring of open‑source dependencies provides audit‑ready proof that you’ve exercised due diligence on third‑party risk.
  • Mapping this technique to your control framework helps you show regulators that you’ve mitigated the risk of malicious code injection from external package registries.

Who Is Affected – Primarily technology and SaaS firms, but any organization that incorporates npm packages into production code (e.g., fintech, e‑commerce, cloud services).

Recommended Actions –

  • Generate and maintain an up‑to‑date Software Bill of Materials (SBOM) for all npm dependencies.
  • Deploy automated scanning tools that flag newly published packages with anomalous metadata or blockchain‑related code.
  • Map findings to SOC 2 CC6.1 (Vendor Management) and retain evidence of remediation for audit reviews.

Source: The Hacker News

Technical Notes – The NullReceiver technique leverages a “dead‑drop resolver” that reads a zero‑value Ethereum transaction, decodes the embedded IP, and contacts the attacker’s C2 server. No CVE is associated; the vector is a malicious third‑party dependency injection. Source: same article

📰 Original Source
https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →