Bleepingcomputer
Malicious NPM Packages Exploit Adspect for Crypto Scams
First seen 2 Dec 2025, 18:33 UTC
•

•85% similarity
•8.5
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Seven malicious packages published on the Node Package Manager (npm) registry have been identified as part of a campaign to redirect users to cryptocurrency scam sites. The packages, published by the developer 'dino_reborn' between September and November 2025, utilize the Adspect cloud service to cloak their activities and distinguish between potential victims and security researchers. The campaign employs various techniques, including fake CAPTCHAs and decoy webpages, to enhance its effectiveness.
ThreatCluster AI
How this analysis works