Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Why Toncoin Is Rising as Telegram Pushes Past Tap-to-Earn

June 2, 2026

FOGNET Partners with SELF to Bring Encrypted AI Services On-Chain

June 2, 2026

HYPE Reaches New All-Time Highs Above $70 – A Legendary Trade Turns Green

June 2, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»New npm Malware Campaign Redirects Victims to Crypto Sites
New npm Malware Campaign Redirects Victims to Crypto Sites
Security and Privacy

New npm Malware Campaign Redirects Victims to Crypto Sites

November 19, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A new malware campaign built around seven npm packages has been uncovered by cybersecurity experts.

The campaign, observed by the Socket Threat Research Team, is operated by a threat actor known as dino_reborn. It uses a mix of cloaking tools, anti-analysis controls and fake crypto-exchange CAPTCHAs to identify whether a visitor is a potential victim or a security researcher.

Six of the packages contain nearly identical 39 KB malware samples, while a seventh constructs a façade webpage.

All seven remained live until takedown requests placed them into security holding. The packages include signals-embed, dsidospsodlks, applicationooks21, application-phskck, integrator-filescrypt2025, integrator-2829 and integrator-2830.

How the Campaign Operated

Each malicious package executed automatically through an IIFE and immediately began collecting a detailed fingerprint of the visiting device. Thirteen data points were gathered, ranging from user agent to language settings. These details were then forwarded through a proxy to the Adspect API, a traffic-cloaking service.

If the Adspect API decided the visitor is a security researcher, the code displayed a “white page” constructed from static assets. If it determined the visitor is a victim, a fake CAPTCHA branded with standx.com, jup.ag or uniswap.org appeared. After a brief delay, the CAPTCHA redirected the victim to a malicious URL supplied by Adspect.

Read more on crypto-focused threat campaigns: New NCA Campaign Warns Men Off Crypto Investment Scams

The malware packages and the façade webpage communicated using shared container IDs. Signals-embed builds the white page that researchers saw, while fallback code inside the malware reconstructed a branded Offlido page if the network failed. Anti-analysis features blocked right-click, F12, Ctrl+U and detected open DevTools, causing the page to reload.

See also  Cybersecurity is a Mess; Can Blockchains Fix It?

Key indicators of this campaign include:

  • Use of /adspect-proxy.php and /adspect-file.php paths

  • JavaScript that disables user interactions

  • Dynamic redirects tied to Adspect stream IDs

Outlook and Defensive Guidance

Socket researchers said this campaign merges open source distribution with techniques traditionally seen in malvertising operations. Because Adspect returns fresh redirect URLs on each request, payloads can shift rapidly. 

“Defenders should expect continued abuse of Adspect-style cloaking and proxy infrastructure in browser-executed open source packages. These tactics will likely reappear with new brand façades and new package names,” the security experts warned.

“Web teams should treat unexpected scripts that disable user interactions or that post detailed client fingerprints to unfamiliar PHP endpoints as immediate red flags. Network defenders should monitor for /adspect-proxy.php and /adspect-file.php paths across any domains, as these serve as reliable indicators of this actor’s toolkit.”

Source link

campaign Crypto Malware npm Redirects Sites Victims
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Revealing the moment crypto started reshaping American elections

June 1, 2026

Anonix Unveils Vision to Turn the XRP Ledger Into an AI-Powered Crypto Marketplace

June 1, 2026

Crypto funds suffer second-largest outflows of 2026 while XRP and HYPE attract inflows

June 1, 2026

Next Crypto Legislation Window Is 2030

June 1, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

XRP Ruling Irks Prominent Congressman

July 29, 2023

Top Altcoins To Watch Next Week: Polygon (MATIC), Litecoin (LTC) And Ripple (XRP) Price To Surge Past Resistance

June 25, 2023

Why SOL is struggling even as Solana’s ecosystem keeps growing

May 4, 2026

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Why Toncoin Is Rising as Telegram Pushes Past Tap-to-Earn

June 2, 2026

FOGNET Partners with SELF to Bring Encrypted AI Services On-Chain

June 2, 2026

HYPE Reaches New All-Time Highs Above $70 – A Legendary Trade Turns Green

June 2, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$70,849.00-3.73%
  • ethereumEthereum(ETH)$2,000.15-0.19%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$691.89-1.32%
  • rippleXRP(XRP)$1.29-3.27%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$80.78-1.98%
  • tronTRON(TRX)$0.341550-2.51%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.042.12%
  • HyperliquidHyperliquid(HYPE)$74.611.73%