Skip to content
Malicious npm Packages Use Adspect Cloaking in Crypto Scam

Malicious npm Packages Use Adspect Cloaking in Crypto Scam

First seen 18 Nov 2025, 18:13 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A malware campaign has been identified that utilizes malicious npm packages to create fake websites designed to identify and exploit potential victims. The threat actor, known as 'dino_reborn', published these packages between September and November 2025, targeting users in the cryptocurrency space.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (12)

Following this threat?

Track 123 Stealer and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed