Malicious NPM Packages Exploit Adspect for Crypto Scams

Malicious NPM Packages Exploit Adspect for Crypto Scams

First seen 2 Dec 2025, 18:33 UTC BleepingcomputerInfosecurity-MagazineScworld 85% similarity 8.5

Article Content

Browse articles
ThreatCluster

Seven malicious packages published on the Node Package Manager (npm) registry have been identified as part of a campaign to redirect users to cryptocurrency scam sites. The packages, published by the developer 'dino_reborn' between September and November 2025, utilize the Adspect cloud service to cloak their activities and distinguish between potential victims and security researchers. The campaign employs various techniques, including fake CAPTCHAs and decoy webpages, to enhance its effectiveness.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story