NullReceiver is a novel command-and-control (C2) technique that encodes the C2 server IP address within the recipient address of a zero-value Ethereum transfer. It improves upon EtherHiding by eliminating a fixed, watchable destination, making detection and attribution more difficult. The technique was observed in trojanized npm packages bianira-ui and fluid-type-ui, linked to North Korean threat actors.