Bleepingcomputer
Malicious NPM Packages Utilize Adspect for Cryptocurrency Scams
First seen 18 Nov 2025, 03:12 UTC
•
•100% similarity
•22.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Seven malicious packages were published on the Node Package Manager (npm) registry, using the Adspect service to redirect users to cryptocurrency scam sites. These packages were uploaded by a developer under the name 'dino_reborn' between September and November 2025, targeting unsuspecting victims while evading detection by security researchers.
ThreatCluster AI
How this analysis works