Skip to content
Malicious NPM Packages Exploit Adspect for Crypto Scams

Malicious NPM Packages Exploit Adspect for Crypto Scams

First seen 2 Dec 2025, 18:33 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

Seven malicious packages published on the Node Package Manager (npm) registry have been identified as part of a campaign to redirect users to cryptocurrency scam sites. The packages, published by the developer 'dino_reborn' between September and November 2025, utilize the Adspect cloud service to cloak their activities and distinguish between potential victims and security researchers. The campaign employs various techniques, including fake CAPTCHAs and decoy webpages, to enhance its effectiveness.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

More articles in this cluster (4)