type: incident ยท created: 2026-08-06 ยท updated: 2026-08-06 ยท tags: [incident, npm, supply-chain, c2-evasion, blockchain] ยท confidence: high ยท affected_sectors: [technology, software-development] ยท au_impact: true
Trojaniased npm Packages Use NullReceiver to Conceal C2 IP in Blockchain
Attackers used malicious (trojaniased) npm packages employing a technique called NullReceiver to conceal command-and-control (C2) IP addresses inside blockchain data โ a supply-chain delivery with the C2 resolved from a decentralised, block-border-resilient source.
| Attribute | Detail |
|---|---|
| Delivery | Malicious npm packages |
| Technique | NullReceiver โ C2 IP embedded in blockchain |
| Benefit | C2 infrastructure hard to block/attribute |
| Source | The Hacker News โ Tier 2/4 |
Encoding C2 endpoints in blockchain data makes takedown and sinkholing harder, marking an evolution toward resilient, decentralised C2 delivery in the software supply chain.