Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses | HappeningNow.news

Cybersecurity

Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals…

Source The Hacker News AI Summary Updated 3h 11m ago
Story intelligence Beta
Freshness Fresh Updated 3h 11m ago
Confidence Checking
Coverage Checking
Views New Be the first to read
Read time 1 min ~48 words

AI Summary

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm package "bianira-ui" and "fluid-type-ui," has been…

Read full article on The Hackernews

AI summaries can be wrong sometimes—always verify important details using the source article.

How AI & Automation are used

More coverage on this topic

C226 stories
View all C2 coverage
SUPPORT HAPPENINGNOW · Independent AI News Intelligence
SUPPORTER MESSAGE

Enjoyed this article? Consider supporting HappeningNow to help keep independent AI-powered news analysis moving forward. Your contribution helps cover infrastructure, AI summaries, and continued platform development.

Support HappeningNow

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Report an issue with this page