Crypto Cloak & Dagger: Malicious NPM Packages Scam Unwary Users
Malicious npm packages are playing a cunning game of “Spot the Researcher,” using Adspect cloaking to show security experts a harmless white page while leading victims on a merry dance to fake crypto sites. It’s like a digital version of “Who Wants to Be Scammed?” with a CAPTCHA twist. Stay alert!

Hot Take:
Who knew npm stood for “Notorious Package Mayhem”? With these sneaky tactics, it’s like the hackers are the Houdinis of the digital world—disappearing from researchers’ sight while making victims’ crypto disappear into thin air! Keep your wallets close and your CAPTCHAs closer, folks!
Key Points:
- Seven malicious npm packages identified, using unique anti-evasion tactics.
- Threat actor “dino_reborn” employs Adspect for cloaking, a rare move in npm attacks.
- The malware differentiates between victims and security researchers.
- Victims redirected to crypto scam sites via fake CAPTCHAs.
- All malicious packages have been removed, but vigilance remains crucial.
Already a member? Log in here
