🚨 Two trojanized npm packages hid a command server’s IP address inside blank Ethereum transfers.
The North Korea-linked NullReceiver technique avoids smart contracts and transaction data, making the attacker’s infrastructure harder for defenders to track.
See how it works: https://t.co/S5cf3BPytf
I sat down with @TakSec and he taught me everything I needed to know about Indirect Prompt Injection using a free custom lab on @hackinghub_io!
https://t.co/gikPheDolh