Threatcluster
Malicious npm Packages Use Adspect Cloaking in Crypto Scam
First seen 18 Nov 2025, 18:13 UTC
•



+7
•99% similarity
•24.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A malware campaign has been identified that utilizes malicious npm packages to create fake websites designed to identify and exploit potential victims. The threat actor, known as 'dino_reborn', published these packages between September and November 2025, targeting users in the cryptocurrency space.
ThreatCluster AI