Threat reportSupply ChainTL-2026-1856
NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packages
NullReceiver (TL-2026-1856), also tracked as Contagious Interview, is a high-severity supply-chain compromise, first published 2026-08-04 and last reviewed 2026-08-13. It is attributed to UNC1069 (North Korea) with high confidence, affects npm bianira-ui, maps to 26 MITRE ATT&CK techniques (T1008, T1027, T1027.010), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 26MITRE ATT&CK
- Actors
- 2UNC1069
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-1856
- Threat ID
- TL-2026-1856
- Also known as
- Contagious Interview, PolinRider, DEV#POPPER, NullReceiver, Wallet-Trail C2
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- UNC1069, APT38
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- technology, finance, cryptocurrency, software-development
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 27
- Updates
- 2026-08-13 · 2 updates · revalidated 1×
Malware and tooling in NullReceiver
Malware and tooling: DEV#POPPER, PolinRider, Socket.IO RAT
How NullReceiver works
NullReceiver is a novel blockchain-based C2 resolution technique that encodes the C2 IP address directly in the bytes of a zero-value, zero-data Ethereum transaction recipient address — not in smart-contract calldata — making it harder to detect than earlier methods like EtherHiding. Discovered in two trojanized npm packages (bianira-ui@1.27.0 and fluid-type-ui@2.0.8) impersonating Tailwind CSS plugins, attributed to the DPRK-linked Contagious Interview campaign. The packages deploy a Node.js RAT that queries Ethereum RPC endpoints to resolve C2 IP 166.88.134.62 from the attacker's reusable wallet, fetches XOR-encrypted payloads, and executes arbitrary code via eval() on every require().
NullReceiver represents the latest evolution in DPRK threat actors' iterative refinement of blockchain-based command-and-control (C2) channels, continuing a trajectory that has moved from obfuscator-driven strings to custom encoding, fixed domains, blockchain resolvers, EtherHiding, and now the wallet-trail technique. Discovered by Amazon Inspector and independently documented by OpenSourceMalware (Paul McCarty) on August 2-3, 2026, NullReceiver was found embedded in two trojanized npm packages: bianira-ui@1.27.0 and fluid-type-ui@2.0.8, both marketed as Tailwind CSS plugin lookalikes with no legitimate functionality.
The technical mechanism is deliberately minimal. The malware hardcodes the Ethereum wallet address 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a belonging to the attacker. At runtime, it performs an HTTPS JSON-RPC query against one of three hardcoded RPC endpoints (1rpc.io/eth, eth.drpc.org, eth.blockscout.com) to retrieve the wallet's most recent outbound transaction. Critically, this transaction is a zero-value, zero-data transfer — the cheapest possible Ethereum transaction shape — with the input field containing only '0x' (empty calldata). The C2 IP address (166.88.134.62) is decoded directly from the first 4 bytes of the recipient address, while trailing bytes spell the ASCII marker string 'helloipbot!!' for operator tooling identification. The malware then connects to the decoded C2 server over HTTP on ports 80 or 443 and fetches XOR-encrypted payloads from paths /0x/ls and /0x/cls, decrypting with a 16-byte key before passing to eval() or executing via node -e, with a prelude binding global.r=require and global.m=module.
The two packages use different obfuscation strategies. bianira-ui@1.27.0 embeds the malicious code as an appended top-level IIFE in plugin.js using \uXXXX unicode escapes for all network identifiers to evade static inspection. fluid-type-ui@2.0.8 hides the code block in src/index.js behind a long run of tab characters that push it off-screen in most editors. Both execute automatically on any require() or import(), with no npm install --ignore-scripts bypass possible since the code runs at module load time, not in a postinstall hook.
NullReceiver differs from EtherHiding in several critical ways. EtherHiding embeds C2 payloads in the calldata field of transactions to a fixed burn address (0x000...dEaD), which creates a predictable blockchain landmark that defenders can continuously monitor. NullReceiver instead encodes the C2 IP in a made-up, disposable recipient address that changes per lookup, with empty calldata, leaving no fixed address to monitor and only minimal on-chain artifacts. The trade-off is capacity: NullReceiver can only fit an IP address or small token, whereas EtherHiding can embed full URLs or scripts. Both techniques share the structural weakness of reusing the same sending wallet across campaigns, making the wallet itself the critical detection surface.
The packages are attributed to the DPRK (North Korea) threat cluster tracked as UNC1069/Sapphire Sleet/BlueNoroff/TA444 under the broader Lazarus Group umbrella, specifically the Contagious Interview campaign (first documented by Palo Alto Unit 42 in November 2023). This campaign has deployed over 1,700 malicious packages across five package ecosystems (npm, PyPI, Go Modules, crates.io, Packagist) since January 2025, with a malware arsenal including BeaverTail, InvisibleFerret, OtterCookie, FlexibleFerret, and WAVESHAPER.V2. The C2 IP 166.88.134.62 is hosted on AS18779 (EGIHosting / Ace Data Centers II, L.L.C., Orem, Utah) and was also used in the July 2026 Joyfill npm supply chain compromise (Socket.IO RAT + OmniStealer), linking the two incidents. The detection tag 'A10-npm3!' embedded in the NullReceiver code provides a campaign-level attribution marker.
Defenders should treat the attacker wallet 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a as a reusable detection beacon, monitor for any npm package containing hardcoded Ethereum wallet addresses or blockchain RPC endpoint queries, expand blockchain analytics beyond smart-contract and calldata-centric heuristics to include zero-value transfers with made-up recipient addresses, and retroactively scan for outbound connections to 166.88.134.62 on ports 80 and 443. The C2 server is mutable by the attacker via new on-chain transactions, making the wallet trace the only persistent detection surface.
MITRE ATT&CK techniques used in TL-2026-1856
Command and Control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer; T1205 Traffic Signaling; T1573 Encrypted Channel; T1573.001 Symmetric Cryptography
Defense Evasion
T1027 Obfuscated Files or Information; T1027.010 Command Obfuscation; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location
Collection
T1056 Input Capture; T1056.001 Keylogging
Execution
T1059 Command and Scripting Interpreter; T1059.007 JavaScript; T1204 User Execution; T1204.002 Malicious File; T1204.005 User Execution: Malicious Library
Initial Access
T1195 Supply Chain Compromise; T1195.001 Compromise Software Dependencies and Development Tools
Credential Access
T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers
Resource Development
T1588.002 Obtain Capabilities: Tool; T1608.001 Stage Capabilities: Upload Malware
Affected products and versions in NullReceiver
- npm — bianira-ui
Vulnerable versions: 1.27.0 - npm — fluid-type-ui
Vulnerable versions: 2.0.8
Remediation for NullReceiver
Immediate actions
- Identify and remove all installations of bianira-ui@1.27.0 and fluid-type-ui@2.0.8 from developer workstations and build systems
- Treat any system where these packages were installed as fully compromised; rotate all secrets, API keys, and credentials from a clean machine
- Block outbound connections to 166.88.134.62 on ports 80 and 443 at network perimeter and internal firewalls
- Block RPC endpoints 1rpc.io/eth, eth.drpc.org, and eth.blockscout.com on non-crypto-development systems
- Scan for post-compromise indicators: unexpected eval() calls, Node.js processes making outbound HTTP connections, and unicode-escaped require() statements in project dependencies
Workarounds
- No patched versions exist for these packages; the packages are entirely malicious with no legitimate functionality
- Use npm audit with OpenSSF malicious-packages feed integration
- Pin dependencies to known-good versions and audit all transitive dependencies for blockchain RPC calls
Longer-term hardening
- Implement npm package provenance verification and maintain a curated allowlist of approved packages and versions
- Deploy runtime detection for blockchain RPC queries from non-crypto-application processes (e.g., UI component libraries querying Ethereum)
- Expand blockchain threat monitoring beyond smart-contract calldata to include zero-value outbound transactions with made-up recipient addresses
- Monitor the reusable attacker wallet 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a for future outbound transactions as an early warning signal
- Integrate OpenSSF malicious-packages feed into CI/CD pipeline to block known malicious packages at install time
- Adopt dependency review tools that flag packages with embedded blockchain RPC queries or hardcoded wallet addresses
Weaknesses (CWE) in NullReceiver
Timeline of NullReceiver
- WageMole campaign (CL-STA-0241) earliest infrastructure timestamps, precursor to DPRK IT worker fraud and developer targeting operations
- EtherHiding blockchain C2 technique first observed in the CLEARFAKE campaign (UNC5142), embedding payloads in smart contract calldata on BNB Smart Chain
- Palo Alto Unit 42 first documents the Contagious Interview campaign, linking DPRK threat actors to fake job interview lures delivering malicious npm packages (BeaverTail, InvisibleFerret)
- DPRK threat actor UNC5342 adopts EtherHiding for Contagious Interview campaign, deploying JADESNOW downloader querying BNB Smart Chain and Ethereum smart contracts
- Google Threat Intelligence formally links EtherHiding technique to DPRK state-sponsored actors, confirming UNC5342 attribution
- UNC1069 compromises the axios npm maintainer account, injecting malicious dependency plain-crypto-js into axios v1.14.1 and v0.30.4 (~100M weekly downloads), deploying WAVESHAPER.V2 RAT
- Contagious Interview campaign expands from npm to five package ecosystems (npm, PyPI, Go Modules, crates.io, Packagist); over 1,700 malicious packages identified since January 2025
- Attacker Ethereum wallet 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a activated, beginning NullReceiver zero-value transactions encoding C2 IP 166.88.134.62 in recipient addresses (68 transactions observed).
- Joyfill npm packages (@joyfill/components, @joyfill/layouts) compromised in parallel incident, deploying Socket.IO RAT and OmniStealer via same C2 infrastructure at 166.88.134.62
- Amazon Inspector detects and flags both packages as malicious; OpenSSF malicious-packages repository publishes OSV advisories MAL-2026-11136 and MAL-2026-11132
- Two trojanized npm packages published: bianira-ui@1.27.0 and fluid-type-ui@2.0.8, impersonating Tailwind CSS plugins, embedding NullReceiver blockchain C2 resolution technique
- bianira-ui and fluid-type-ui removed from the npm registry after accumulating 696 cumulative downloads (109 for bianira-ui, 587 across fluid-type-ui 2.0.8/2.0.9).
- OpenSourceMalware (Paul McCarty) publishes NullReceiver technical analysis, detailing wallet-trail C2 technique and distinguishing it from EtherHiding
- GBHackers publishes NullReceiver article bringing technique to wider cybersecurity audience; TL-Intel Harness research phase executed
- Additional security media (The Hacker News, Cybersecurity News, Cybercory, ZeroWL) publish coverage of the NullReceiver campaign, amplifying IOCs and defensive guidance.
Update history for TL-2026-1856
- 2026-08-13 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s), 63 community-related indicator(s).
- 2026-08-05 — Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain (DPRK): What changed No severity, exploitability, or status escalation — both reports agree HIGH / ACTIVE / ACTIVE. The update expands MITRE coverage (Resource Development T1588.002/T1608.001, T1204.005, T1027.013, Fallback Channels T1008, Ingress
Sources cited for NullReceiver
- GBHackers: NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet
- OpenSourceMalware / Mallory: NullReceiver Wallet-Trail Analysis
- OSV MAL-2026-11136: fluid-type-ui malicious package
- OSV MAL-2026-11132: bianira-ui malicious package
- GitHub Advisory GHSA-44q9-v3f9-xcx6: fluid-type-ui malicious code
- GitHub Advisory GHSA-4w4v-pw3v-q85q: fluid-type-ui (alias)
- CSA Research Note: DPRK Contagious Interview Cross-Ecosystem Expansion
- Socket.dev: Joyfill npm Beta Releases Compromised
- Attestd: Joyfill npm Compromise DPRK Attribution
- StepSecurity: Joyfill npm Supply Chain Compromise Analysis
- OSSF Malicious Packages: fluid-type-ui OSV JSON
- OSSF Malicious Packages: bianira-ui OSV JSON
- NPM Page: fluid-type-ui@2.0.8
- NPM Page: bianira-ui@1.27.0
Detection coverage for TL-2026-1856
As of 2026-08-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1856 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.