Seven Malicious npm Packages Redirect Users to Crypto Scams

Seven Malicious npm Packages Published by Threat Actor ‘dino_reborn’ Using Cloaking Service Adspect to Redirect Users to Suspicious Crypto Websites

  • Seven malicious npm packages were published by one threat actor between September and November 2025.
  • The threat actor used a cloaking service named Adspect to distinguish real victims from security researchers.
  • These packages redirect victims to suspicious crypto-themed websites.
  • The packages were attributed to a threat actor going by “dino_reborn”.

Between September and November 2025, Cybersecurity researchers identified seven malicious npm packages published by a single threat actor. These packages were linked to the user “dino_reborn” and are designed to redirect users to questionable crypto-related websites.

- Advertisement -

The threat actor employs a cloaking service called Adspect, which helps differentiate between genuine victims and security researchers investigating the packages. This selective targeting enhances the chances of deceiving real users while avoiding detection. Npm packages are collections of code published on the Node Package Manager platform, commonly used for software development.

The discovery highlights the increasing use of sophisticated techniques like cloaking to distribute malicious content. By filtering visitors based on their identity, attackers improve their chances of successfully executing scams that target cryptocurrency users.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Critical Flaws Found in Anthropic’s Claude Code AI

Researchers at Check Point disclosed critical vulnerabilities in Anthropic's Claude Code AI assistant.The flaws,...

Tesla Shifts to AI, Robots Amid Vehicle Sales Decline

Tesla is shifting factory production from its Model S and X to manufacture its...

Crypto Shorts Liquidated as Bitcoin Surges to $69K

Major cryptocurrencies like Bitcoin (BTC), Ethereum (ETH), and Solana (SOL) surged, leading to millions...

Syracuse Adopts AWS AI Chips on Theta EdgeCloud

Syracuse University will adopt AWS Trainium on Theta EdgeCloud Hybrid for cutting-edge generative AI...

UK Politicians Urge Temporary Ban on Crypto Donations

A UK parliamentary committee has called for a temporary ban on cryptocurrency donations to...

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!