← Back to the feed

~/article/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-99tpp1
infoSource: The Hacker News

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by

Read at the source

Summary written for cymesh.dev. The full article lives at The Hacker News.

~/cymesh.net

Certificates expire quietly

cymesh.net watches your TLS and SSL certificates and warns you before one lapses.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/trojanized-npm-packages-employ-nullreceiver-tactic-to-decode-c2-ip-from-99tpp1