Malicious npm Packages Use Adspect Cloaking in Crypto Scam

Malicious npm Packages Use Adspect Cloaking in Crypto Scam

First seen 2 Dec 2025, 18:33 UTC ThehackernewsDarkreading 8.3

Article Content

Browse articles
ThreatCluster

A malware campaign exploits seven malicious npm packages published by the threat actor 'dino_reborn' to deceive users into visiting fraudulent crypto scam websites. These packages utilize adspect cloaking techniques to differentiate between potential victims and security researchers, enabling targeted scams. The packages were published between September and November 2025.