Malicious npm Packages Target Crypto Users in Sophisticated Attack
Cybersecurity researchers have uncovered seven malicious npm packages published by a single threat actor, 'dino_reborn,' between September and November 2025. These packages—signals-embed, dsidospsodlks, applicationooks21, application-phskck, integrator-filescrypt2025, integrator-2829, and integrator-2830—collectively garnered over 1,600 downloads, posing a significant risk to crypto users.
The attack employs a deceptive CAPTCHA scheme to redirect victims to malicious sites while evading security researchers. Socket researcher Olivia Brown notes the threat actor's ability to distinguish between targets and analysts, highlighting the sophistication of the campaign.
Separately, Adspect, a cloud-based service claiming to protect ad campaigns, raises red flags with its 'bulletproof cloaking' technology and no-questions-asked policy. The service's premium pricing tiers—$299 to $999 monthly—and permissive content rules suggest potential misuse in crypto-related advertising schemes.