Ethereum Transactions as C2 for npm Supply-Chain Attacks
Six npm packages use Ethereum transactions as dead drops to retrieve malicious payloads via NullReceiver technique, querying multiple RPC providers. Bypasses traditional network monitoring. Reinforces need for runtime monitoring beyond provenance.
Sources (1)
Updated Aug 14, 2026