SIX npm packages have been identified as querying a malicious Ethereum wallet to retrieve command-and-control (C2) addresses, allowing them to fetch malware payloads. Research by Sonatype revealed that all identified packages contain the same payload and are tracked under specific identifiers. The technique, termed 'NullReceiver,' is linked to North Korean hacker activities associated with the Lazarus group.
The loader mechanism utilized by these packages queries Ethereum transactions to extract C2 endpoints, demonstrating advanced evasion tactics. The affected npm packages include both hijacked legitimate packages and those published with malware embedded. Remediation involves checking environments for the affected versions and investigating signs of compromise.