# North Korea Buried Its C2 Address Inside a Fake Ethereum Transfer — Then Left a Note
The payload was already on your machine before you noticed anything wrong. Two npm packages — bianira-ui and fluid-type-ui — sat in the registry for eight days, collecting a combined 696 downloads before researchers at OpenSourceMalware pulled the thread. What they found wasn't just another supply chain hit. It was evidence that North Korean operators had quietly iterated their blockchain-based command infrastructure into something meaningfully harder to detect and track.
The technique is called NullReceiver. And the people who built it left "helloipbot!!" encoded in the address bytes, apparently for fun.
## How You Hide a Server Address on a Blockchain Nobody's Watching
To understand why NullReceiver matters, you need to know what came before it.
EtherHiding, first documented by Guardio Labs in October 2023, worked by embedding malicious payloads — including C2 IP addresses — inside smart contract data on public blockchains like Ethereum or BNB Smart Chain. The appeal for attackers was obvious: blockchain transactions are immutable and globally replicated, so you can't take down the "hosting" the way you'd seize a domain. Defenders adapted by watching for transactions to known smart contract addresses, creating a watchlist they could update as new infrastructure emerged.
NullReceiver closes that gap by eliminating the fixed destination entirely.
Here's the mechanics: the malware hard-codes a single attacker wallet address (0xa322e5f3d311d3080e6f0121063e9adc2490ef1a). It queries that wallet, finds its most recent outbound transaction, and reads the destination address — not the transaction data, not a smart contract call, just the To field. The destination doesn't need to be a real Ethereum account. It doesn't need to exist at all. It just needs to be 20 bytes that, when you pull the first four and convert from hex to decimal, give you an IP address.
In the observed transactions, that destination was 0xa658863ea658863e68656c6c6f6970626f742121. The first four bytes — a658863e — decode to 166.88.134[.]62. The trailing twelve bytes decode to something else: the ASCII string helloipbot!!.
There's no smart contract. There's no calldata. There's a zero-value transfer to a phantom address with a joke buried inside it. The entire C2 lookup costs the operator a transaction fee and produces nothing a static watchlist would flag.
## Contagious Interview's Infrastructure Gets an Upgrade
Attribution here points to North Korea's Contagious Interview campaign, a long-running operation that Google Threat Intelligence Group detailed late last year. The playbook is consistent: approach developers on LinkedIn with a job opportunity, ask them to complete a technical assessment, and deliver malware through the process. The targets are typically software developers — people who install npm packages without a second thought because it's what their job requires.
The choice of bianira-ui and fluid-type-ui as package names signals deliberate intent. These aren't generic utility names. They mimic UI component libraries — the kind of thing a developer evaluating a new frontend framework or building a quick prototype would grab. The user accounts that published them, npmuser1101 and npmuser3002, are throwaways with sequential numbering, suggesting automated or semi-automated account creation at scale.
The download counts are telling. fluid-type-ui pulled 587 installs against bianira-ui's 109. That asymmetry probably reflects when each package was seeded into the campaign — and possibly which targets were handed a specific package as part of their "assessment."
## What Changes for Defenders
The defenders' previous advantage with EtherHiding was predictability. If you knew a campaign was using a specific smart contract address or a consistent calldata structure, you could write detection rules. You could watch for outbound calls to known blockchain APIs combined with subsequent connections to suspicious IPs.
NullReceiver disrupts that pattern in two ways. First, the phantom destination address changes every time the operator rotates their C2 infrastructure — a new zero-value transfer to a new nonsense address updates the IP. Second, the attacker wallet itself is the only fixed element, and that wallet can be abandoned and replaced at will. Without the smart contract anchor, there's no "fixed, watchable destination," as researcher Paul McCarty put it.
Detection now has to move toward behavior: JavaScript that calls blockchain data APIs (Etherscan, Infura, Alchemy) shortly after package installation, followed by socket connections to IP addresses extracted from transaction metadata. That's a more complex detection chain and one that generates more false positives in environments where developers legitimately query blockchain APIs.
---
## HackWire Analysis
The "helloipbot!!" string reads like a taunt, but it's probably just developer culture bleeding through — an internal joke in a debug string that nobody bothered to sanitize before production. What's genuinely significant is what that sloppiness reveals: these operators are moving fast and iterating. NullReceiver didn't emerge from a long R&D cycle. It's a targeted fix for a specific operational problem that defenders had started to solve.
This is the loop that should concern anyone running developer-facing infrastructure. EtherHiding was documented publicly in October 2023. Within roughly two years, the same threat actors had produced a successor that eliminates the primary detection surface defenders built around the first technique. The publication of research that helps defenders is also a blueprint for attackers to improve.
The npm ecosystem's weak identity verification — sequential numbered usernames, no meaningful vetting — continues to be the lowest-friction entry point for supply chain attacks at scale. 696 downloads is small, but Contagious Interview has never been about mass infection. It's about surgical compromise of developers with access to valuable systems, codebases, or crypto wallets.
Security teams running developer endpoints should be hunting for the behavioral pattern: npm install events followed by blockchain API calls followed by outbound connections. Blocking Etherscan and similar APIs at the perimeter is blunt but effective. The real fix is npm's identity problem, which the ecosystem has discussed for years without resolving it.
The "helloipbot!!" message was left for the malware's own use — a human-readable label inside what would otherwise be random bytes. The researchers found it anyway. That's the only comfort here.
— HackWire Editorial
---
## Related Coverage