logo

Malicious NPM packages abuse Adspect redirects to evade security

ID: 567ce3b2-0795-5bff-8922-9f83b3ab600b

STIX ID: report--567ce3b2-0795-5bff-8922-9f83b3ab600b

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2025-11-17

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Researchers found seven npm packages published by a single account that include malicious JavaScript which fingerprints visitors, evades analysis (blocks DevTools, right-click, etc.), and uses the Adspect API to distinguish researchers from real victims before redirecting targeted users to fake cryptocurrency scam pages; one package appears to be a decoy. The report highlights supply-chain abuse on the npm registry and documents package names and the cloaking/fingerprinting TTPs used to enable fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.