Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-06 ยท updated: 2026-08-06 ยท tags: [incident, npm, supply-chain, c2-evasion, blockchain] ยท confidence: high ยท affected_sectors: [technology, software-development] ยท au_impact: true

Trojaniased npm Packages Use NullReceiver to Conceal C2 IP in Blockchain

Attackers used malicious (trojaniased) npm packages employing a technique called NullReceiver to conceal command-and-control (C2) IP addresses inside blockchain data โ€” a supply-chain delivery with the C2 resolved from a decentralised, block-border-resilient source.

Attribute Detail
Delivery Malicious npm packages
Technique NullReceiver โ€” C2 IP embedded in blockchain
Benefit C2 infrastructure hard to block/attribute
Source The Hacker News โ€” Tier 2/4

Encoding C2 endpoints in blockchain data makes takedown and sinkholing harder, marking an evolution toward resilient, decentralised C2 delivery in the software supply chain.

Source