Thehackernews
Malicious npm Packages Use Adspect Cloaking in Crypto Scam
First seen 2 Dec 2025, 18:33 UTC
•
•8.3
Export
Article Content
Browse articles
A malware campaign exploits seven malicious npm packages published by the threat actor 'dino_reborn' to deceive users into visiting fraudulent crypto scam websites. These packages utilize adspect cloaking techniques to differentiate between potential victims and security researchers, enabling targeted scams. The packages were published between September and November 2025.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
NPM Packages Distribute PylangGhost RAT in Supply Chain Attack