Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam
ID: 710723cc-9e75-512c-ada6-e6bc58fe0929
STIX ID: report--710723cc-9e75-512c-ada6-e6bc58fe0929
Feed Name: Dark Reading
Date Published: 2025-11-18
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers discovered seven malicious npm packages that execute browser-side malware to fingerprint visitors and, via the Adspect cloaking service and a proxy, selectively show fake CAPTCHAs then redirect non-researcher victims to cryptocurrency scam websites; the packages have been removed from npm, and analysts provided package names, proxy/Adspect endpoint indicators, and recommended detection strings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
