
DPRK NullReceiver Malware Hides C2 IPs in Zero-Value Ethereum Transactions
Researchers have identified a new DPRK-linked npm malware technique that hides command-and-control (C2) infrastructure inside ordinary Ethereum transactions. Named NullReceiver, the method was found in two trojanized npm packages, [email protected] and [email protected], which impersonate legitimate Tailwind CSS plugins. The packages are linked to the DPRK’s Contagious Interview campaign. Instead of embedding a malicious domain or […]
The post DPRK NullReceiver Malware Hides C2 IPs in Zero-Value Ethereum Transactions appeared first on Cyber Security News.