Skip to content
Malicious npm Packages Use Adspect Cloaking in Crypto Scam

Malicious npm Packages Use Adspect Cloaking in Crypto Scam

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A malware campaign exploits seven malicious npm packages published by the threat actor 'dino_reborn' to deceive users into visiting fraudulent crypto scam websites. These packages utilize adspect cloaking techniques to differentiate between potential victims and security researchers, enabling targeted scams. The packages were published between September and November 2025.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (2)