View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

North Korean Hackers Hide Malware Servers in Empty Ethereum

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • North Korean Hackers Hide Malware Servers in Empty Ethereum Transactions North Korean hackers use empty Ethereum transactions to conceal malware command servers.
    • Targets developers via malicious npm packages bianira-ui@1.27.0 and fluid-type-ui@2.0.8
    • Malware hides command-and-control server IP in recipient address of empty Ethereum transfers
    • Uses public Ethereum RPC services https://1rpc.io/eth and https://eth.drpc.org to retrieve commands
    • Technique named NullReceiver linked to DPRK Contagious Interview operation supply-chain attacks
    • Command server IP decoded as 166.88.134.62 with HTTP/HTTPS endpoints on ports 80 and 443 ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ”“ CVEs & KEV

  • CVE-2026-18569 โ€” CVSS 3.7 โ€” Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned requests
  • CVE-2026-68744 โ€” CVSS 3.3 โ€” Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply
  • CVE-2026-18739 โ€” CVSS 2.5 โ€” Popt-devel: popt-static: off-by-one in poptstuffargs
  • CVE-2026-16881 โ€” CVSS unknown โ€” A code injection vulnerability exists in the LINE Android app prior to version X

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check