• Sources: analysis, discussion
  • Summary: Two trojanized Tailwind CSS plugin clones, bianira-ui@1.27.0 and fluid-type-ui@2.0.8, decode a command-and-control IP address from the destination address bytes of a zero-value, zero-data Ethereum transfer. The transfer carries no calldata and no funds, so the address field is the entire payload.
  • Why it matters: Detections built around EtherHiding's fixed burn address and calldata inspection do not fire on this variant.
  • Follow-up: Track the opensourcemalware.com NullReceiver series for further packages using the same encoding.

send feedback on this story