# NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packages

> NullReceiver is a novel blockchain-based C2 resolution technique that encodes the C2 IP address directly in the bytes of a zero-value, zero-data Ethereum transaction recipient address — not in smart-contract calldata — making it harder to detect than earlier methods like EtherHiding. Discovered in two trojanized npm packages (bianira-ui@1.27.0 and fluid-type-ui@2.0.8) impersonating Tailwind CSS plugins, attributed to the DPRK-linked Contagious Interview campaign. The packages deploy a Node.js RAT that queries Ethereum RPC endpoints to resolve C2 IP 166.88.134.62 from the attacker's reusable wallet, fetches XOR-encrypted payloads, and executes arbitrary code via eval() on every require().

- **Published:** 2026-08-04T00:00:00Z
- **Last reviewed:** 2026-08-13T10:34:14Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1856
- **ID:** TL-2026-1856
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** UNC1069 (North Korea)
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

NullReceiver represents the latest evolution in DPRK threat actors' iterative refinement of blockchain-based command-and-control (C2) channels, continuing a trajectory that has moved from obfuscator-driven strings to custom encoding, fixed domains, blockchain resolvers, EtherHiding, and now the wallet-trail technique. Discovered by Amazon Inspector and independently documented by OpenSourceMalware (Paul McCarty) on August 2-3, 2026, NullReceiver was found embedded in two trojanized npm packages: bianira-ui@1.27.0 and fluid-type-ui@2.0.8, both marketed as Tailwind CSS plugin lookalikes with no legitimate functionality.

The technical mechanism is deliberately minimal. The malware hardcodes the Ethereum wallet address 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a belonging to the attacker. At runtime, it performs an HTTPS JSON-RPC query against one of three hardcoded RPC endpoints (1rpc.io/eth, eth.drpc.org, eth.blockscout.com) to retrieve the wallet's most recent outbound transaction. Critically, this transaction is a zero-value, zero-data transfer — the cheapest possible Ethereum transaction shape — with the input field containing only '0x' (empty calldata). The C2 IP address (166.88.134.62) is decoded directly from the first 4 bytes of the recipient address, while trailing bytes spell the ASCII marker string 'helloipbot!!' for operator tooling identification. The malware then connects to the decoded C2 server over HTTP on ports 80 or 443 and fetches XOR-encrypted payloads from paths /0x/ls and /0x/cls, decrypting with a 16-byte key before passing to eval() or executing via node -e, with a prelude binding global.r=require and global.m=module.

The two packages use different obfuscation strategies. bianira-ui@1.27.0 embeds the malicious code as an appended top-level IIFE in plugin.js using \uXXXX unicode escapes for all network identifiers to evade static inspection. fluid-type-ui@2.0.8 hides the code block in src/index.js behind a long run of tab characters that push it off-screen in most editors. Both execute automatically on any require() or import(), with no npm install --ignore-scripts bypass possible since the code runs at module load time, not in a postinstall hook.

NullReceiver differs from EtherHiding in several critical ways. EtherHiding embeds C2 payloads in the calldata field of transactions to a fixed burn address (0x000...dEaD), which creates a predictable blockchain landmark that defenders can continuously monitor. NullReceiver instead encodes the C2 IP in a made-up, disposable recipient address that changes per lookup, with empty calldata, leaving no fixed address to monitor and only minimal on-chain artifacts. The trade-off is capacity: NullReceiver can only fit an IP address or small token, whereas EtherHiding can embed full URLs or scripts. Both techniques share the structural weakness of reusing the same sending wallet across campaigns, making the wallet itself the critical detection surface.

The packages are attributed to the DPRK (North Korea) threat cluster tracked as UNC1069/Sapphire Sleet/BlueNoroff/TA444 under the broader Lazarus Group umbrella, specifically the Contagious Interview campaign (first documented by Palo Alto Unit 42 in November 2023). This campaign has deployed over 1,700 malicious packages across five package ecosystems (npm, PyPI, Go Modules, crates.io, Packagist) since January 2025, with a malware arsenal including BeaverTail, InvisibleFerret, OtterCookie, FlexibleFerret, and WAVESHAPER.V2. The C2 IP 166.88.134.62 is hosted on AS18779 (EGIHosting / Ace Data Centers II, L.L.C., Orem, Utah) and was also used in the July 2026 Joyfill npm supply chain compromise (Socket.IO RAT + OmniStealer), linking the two incidents. The detection tag 'A10-npm3!' embedded in the NullReceiver code provides a campaign-level attribution marker.

Defenders should treat the attacker wallet 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a as a reusable detection beacon, monitor for any npm package containing hardcoded Ethereum wallet addresses or blockchain RPC endpoint queries, expand blockchain analytics beyond smart-contract and calldata-centric heuristics to include zero-value transfers with made-up recipient addresses, and retroactively scan for outbound connections to 166.88.134.62 on ports 80 and 443. The C2 server is mutable by the attacker via new on-chain transactions, making the wallet trace the only persistent detection surface.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1195.001 Compromise Software Dependencies and Development Tools
- T1059 Command and Scripting Interpreter
- T1059.007 JavaScript
- T1204 User Execution
- T1204.002 Malicious File
- T1102.002 Bidirectional Communication
- T1071 Application Layer Protocol
- T1071.001 Web Protocols
- T1573 Encrypted Channel
- T1573.001 Symmetric Cryptography
- T1205 Traffic Signaling
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1027.010 Command Obfuscation
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers
- T1056 Input Capture
- T1056.001 Keylogging
- T1588.002 Obtain Capabilities: Tool
- T1608.001 Stage Capabilities: Upload Malware
- T1204.005 User Execution: Malicious Library
- T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
- T1008 Fallback Channels
- T1105 Ingress Tool Transfer

## Sources

- [GBHackers: NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet](https://gbhackers.com/nullreceiver-wallet-trail/)
- [OpenSourceMalware / Mallory: NullReceiver Wallet-Trail Analysis](https://mallory.ai/stories/019fbfce-ef8a-7f5e-8967-b23572a63b8a)
- [OSV MAL-2026-11136: fluid-type-ui malicious package](https://osv.dev/vulnerability/MAL-2026-11136)
- [OSV MAL-2026-11132: bianira-ui malicious package](https://osv.dev/vulnerability/MAL-2026-11132)
- [GitHub Advisory GHSA-44q9-v3f9-xcx6: fluid-type-ui malicious code](https://github.com/advisories/GHSA-44q9-v3f9-xcx6)
- [GitHub Advisory GHSA-4w4v-pw3v-q85q: fluid-type-ui (alias)](https://github.com/advisories/GHSA-4w4v-pw3v-q85q)
- [CSA Research Note: DPRK Contagious Interview Cross-Ecosystem Expansion](https://labs.cloudsecurityalliance.org/research/csa-research-note-dprk-contagious-interview-cross-ecosystem/)
- [Socket.dev: Joyfill npm Beta Releases Compromised](https://socket.dev/blog/joyfill-npm-beta-releases-compromised)
- [Attestd: Joyfill npm Compromise DPRK Attribution](https://www.attestd.io/blog/joyfill-npm-compromised-blockchain-c2-north-korea)
- [StepSecurity: Joyfill npm Supply Chain Compromise Analysis](https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise)
- [OSSF Malicious Packages: fluid-type-ui OSV JSON](https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fluid-type-ui/MAL-2026-11136.json)
- [OSSF Malicious Packages: bianira-ui OSV JSON](https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bianira-ui/MAL-2026-11132.json)
- [NPM Page: fluid-type-ui@2.0.8](https://www.npmjs.com/package/fluid-type-ui/v/2.0.8)
- [NPM Page: bianira-ui@1.27.0](https://www.npmjs.com/package/bianira-ui/v/1.27.0)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1856
