- Sources: analysis, discussion
- Summary: Two trojanized Tailwind CSS plugin clones, bianira-ui@1.27.0 and fluid-type-ui@2.0.8, decode a command-and-control IP address from the destination address bytes of a zero-value, zero-data Ethereum transfer. The transfer carries no calldata and no funds, so the address field is the entire payload.
- Why it matters: Detections built around EtherHiding's fixed burn address and calldata inspection do not fire on this variant.
- Follow-up: Track the opensourcemalware.com NullReceiver series for further packages using the same encoding.
send feedback on this story