# How North Korea Turned a Phantom Ethereum Address Into a Malware Switchboard
Two npm packages sat on the registry for eight days before researchers noticed. By then, 696 developers had downloaded them — and every one of those machines was quietly checking a blockchain wallet for instructions.
The packages, bianira-ui and fluid-type-ui, carried a technique the researchers at OpenSourceMalware are calling NullReceiver. It's an evolution of a North Korean trick already considered near-bulletproof. And the upgrade is genuinely clever in ways that should worry anyone defending a software supply chain.
## Zero Value, Maximum Payload
To understand NullReceiver, you first need to understand what it improved on.
EtherHiding, first documented by Guardio Labs in October 2023, hid malware configurations and C2 addresses inside smart contract transaction data on public blockchains like BNB Smart Chain. The appeal was obvious: blockchain data is immutable, globally distributed, and doesn't have a registrar you can call to pull a domain. Traditional C2 takedowns — seize the server, kill the domain — don't apply.
But EtherHiding had a seam defenders could exploit. It required a fixed, known destination address. Once you knew that address, you could watch it. Every time the attacker sent a new transaction with an updated C2 IP or payload, that transaction was visible, attributable, and tied to a wallet that had a public history.
NullReceiver plugs that gap in an uncomfortably elegant way. Instead of embedding data in transaction calldata — a field that exists for arbitrary data — it encodes the C2 IP address directly inside the recipient address itself. No smart contract. No calldata. Just a zero-value transfer from a hard-coded attacker wallet to a destination address that has no corresponding account, no owner, and exists solely to carry four bytes of encoded IPv4 address.
The infected packages retrieve the attacker's wallet (0xa322e5f3d311d3080e6f0121063e9adc2490ef1a), find its most recent outbound transaction, read the "To" address, and decode an IP from the first four bytes. In the observed campaign, that resolved to 166.88.134[.]62.
There's a detail buried in the transaction metadata that deserves its own sentence: the trailing bytes of those destination addresses spell out helloipbot!! in ASCII. Someone on the other end thought that was funny.
## The Fixed Wallets Aren't Going Away
The one remaining hook for defenders is the hard-coded wallet address itself. The attacker still has to publish transactions from a known wallet for this to work. Monitoring Ethereum transactions from 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a will tell you when the C2 IP rotates — and rotating it costs nothing more than a zero-value transfer.
That's meaningfully worse than EtherHiding's fixed destination address. Before, defenders could watch one specific address and know every time an update was pushed. Now, the destination address changes with every C2 rotation, making it useless as a signature. The wallet address itself is static, but attributing real-world identity to an Ethereum wallet is not a fast process — and the attacker only needs the IP to stay live long enough to complete the initial handshake and establish persistence.
The asymmetry is notable: the attacker pays a nominal gas fee to rotate their infrastructure. Defenders need to run continuous blockchain monitoring against a growing list of suspected wallets and correlate those observations with npm package installs happening across thousands of organizations.
## Contagious Interview, Continuous Improvement
Both packages trace back to the Contagious Interview campaign, a North Korean operation GTIG documented last year. The playbook: approach developers on LinkedIn with lucrative job offers, ask them to complete a coding assessment, serve them a package that contains the malware. The technical skill required to complete the assessment keeps the victim pool relevant — these aren't random targets, they're developers with access to codebases, credentials, and potentially significant cryptocurrency holdings.
The campaign has been running for years and the TTPs keep sharpening. Three years ago it was simple malicious npm packages with hardcoded IPs. Then EtherHiding. Now NullReceiver. Each iteration makes detection harder and takedown more expensive.
bianira-ui pulled 109 downloads. fluid-type-ui pulled 587. Those numbers seem small until you remember that a developer who runs npm install on a work machine may have access to production deploy keys, internal repositories, and corporate credentials. One infected dependency can radiate outward.
## What Defenders Should Actually Do
The detection signature here is behavioral, not static. A UI library — something named bianira-ui or fluid-type-ui — has zero legitimate reason to query the Ethereum blockchain. Any npm package making outbound calls to Etherscan or similar APIs during install or runtime is worth treating as hostile until proven otherwise.
Specifically:
node_modules for Ethereum API calls. Grep for etherscan, infura, web3, or similar references in packages you didn't explicitly intend to pull blockchain functionality from.npm install. Tools like socket.dev or simply running installs in a sandboxed environment with network logging can surface anomalous outbound calls before they execute on developer machines.bianira-ui or fluid-type-ui appear in any package-lock.json or yarn.lock in your org's repositories, treat the machine that installed them as compromised.0xa322e5f3d311d3080e6f0121063e9adc2490ef1a is now a known attacker wallet — any process on your infrastructure querying its transaction history is a hard indicator of compromise.---
## HackWire Analysis
The "helloipbot!!" message embedded in the transaction addresses is easy to dismiss as an Easter egg, but it's actually diagnostic. This isn't the work of a rushed operation — it's a group comfortable enough with their method that they're leaving signatures. That confidence is earned: the Contagious Interview campaign has operated for years with relatively limited disruption to its core infrastructure despite being publicly documented by Mandiant, GTIG, and others.
What strikes me about NullReceiver is that it solves the exact problem sophisticated defenders raised about EtherHiding. It reads like a direct response to the published threat intelligence — which implies the operators are watching what we write. That's not unusual for nation-state groups, but the turnaround from "documented weakness in EtherHiding" to "deployed fix in NullReceiver" is fast enough to suggest active, iterative development rather than one-off malware drops.
The supply chain angle also matters for a reason the technical coverage tends to underplay: Contagious Interview's victim selection is deliberate. These aren't phishing emails blasted at millions. LinkedIn outreach to developers implies targeting — probably cross-referenced against GitHub profiles, public repositories, or prior crypto project involvement. A developer who's contributed to a DeFi project or holds meaningful crypto assets is a better target than a random engineer, and North Korea's track record in cryptocurrency theft is well-documented.
The narrow download numbers (696 combined) should not be reassuring. With targeted supply chain attacks, one developer at the right company is worth a thousand random installs. The question for any organization with a significant developer workforce or crypto custody is not "were we in the 696?" but "what's our npm install surface, and are we actually watching it?"
The blockchain-as-C2 trend predates NullReceiver and will outlast it. Expect a NullReceiver successor within twelve months that makes the wallet address itself dynamic — perhaps derived from a public on-chain event. At that point, the only reliable detection surface is behavioral, not IOC-based.
— HackWire Editorial
---
## Related Coverage