#Adspect
Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations.
Malicious NPM packages abuse Adspect redirects to evade security
Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations.
www.bleepingcomputer.com
November 17, 2025 at 11:48 PM
🚨 New npm malware campaign uncovered: 7 malicious packages use Adspect cloaking and fake CAPTCHAs to hide redirects to #crypto scam sites.

Read the full analysis → socket.dev/blog/npm-mal...
npm Malware Campaign Uses Adspect Cloaking to Deliver Malici...
Malicious npm packages use Adspect cloaking and fake CAPTCHAs to fingerprint visitors and redirect victims to crypto-themed scam sites.
socket.dev
November 17, 2025 at 3:00 PM
Seven Malicious NPM Packages Use Adspect to Redirect to Crypto Scams

#Adspect #cryptoscams #JavaScript #maliciouspackages #NPM
Seven Malicious NPM Packages Use Adspect to Redirect to Crypto Scams
Cybersecurity researchers have uncovered seven malicious JavaScript packages on NPM that utilize Adspect, a commercial cloaking service. These packages are
blazetrends.com
November 19, 2025 at 12:11 AM
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages

#thehackersnews
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages
Malicious npm packages use Adspect cloaking to filter victims and deliver crypto-themed redirects.
thehackernews.com
November 18, 2025 at 2:30 PM
npmマルウェアキャンペーン、Adspect Cloakingを介して悪意のあるリダイレクトを配信
#CybersecurityNews
socket.dev/blog/npm-mal...
npm Malware Campaign Uses Adspect Cloaking to Deliver Malici...
Malicious npm packages use Adspect cloaking and fake CAPTCHAs to fingerprint visitors and redirect victims to crypto-themed scam sites.
socket.dev
November 19, 2025 at 7:22 AM
悪意のあるnpmパッケージが暗号詐欺のクローキング機能を悪用

Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam #DarkReading (Nov 19)

www.darkreading.com/application-...
Malicious Npm Packages Abuse Adspect Cloaking
A malware campaign presents fake websites that can check if a visitor is a victim or a researcher, and then proceed accordingly to defraud or evade
www.darkreading.com
November 19, 2025 at 9:30 AM
Notícia da BleepingComputer

"Malicious NPM packages abuse Adspect redirects to evade security" #bolhasec
Malicious NPM packages abuse Adspect redirects to evade security
Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations.
www.bleepingcomputer.com
January 12, 2026 at 9:30 PM
Notícia da BleepingComputer

"Malicious NPM packages abuse Adspect redirects to evade security" #bolhasec
Malicious NPM packages abuse Adspect redirects to evade security
Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations.
www.bleepingcomputer.com
November 29, 2025 at 3:30 PM
📰 Paket NPM Berbahaya Manfaatkan Redirect Adspect untuk Mengelabui Sistem Keamanan

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2025/11/18/malicious-npm-packages-adspect/

#ads
pe#adspectt#crypto#cyber#cybersecuritys#javascripta#malware##npml#supply
November 18, 2025 at 3:02 PM
Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam
Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam
www.darkreading.com
November 28, 2025 at 5:56 AM
Rock, tracked as The Quarry, runs a MaaS/PhaaS toolkit for tax-themed phishing campaigns against U.S. victims using RMM software, cloaking, and Telegram reporting. #Rock #IRS #USA
Dark Web Profile: Rock
Rock, tracked by SOCRadar as The Quarry, is a one-person MaaS/PhaaS operation that sells a full phishing and remote access toolkit to affiliates running tax-themed campaigns against U.S. victims. The ecosystem uses legitimate RMM software, Adspect cloaking, and Telegram-based reporting to support campaigns impersonating the IRS, SSA, Adobe, Dropbox, DocuSign, and Messenger. #TheQuarry #Rock #ScreenConnect #Adspect #Telegram #IRS #SSA #Adobe #Dropbox #DocuSign #Messenger
www.hendryadrian.com
June 13, 2026 at 5:15 AM
A malware campaign since Jan 2026 uses Google Ads with tax search lures to deliver ScreenConnect installers deploying HwAudKiller, a Huawei driver that disables EDRs and enables LSASS credential dumping in the US. #HwAudKiller #ScreenConnect #USA
Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR
A large-scale malvertising campaign since January 2026 has used Google Ads to lure U.S. tax-searching victims into downloading rogue ConnectWise Control installers that deploy a BYOVD EDR killer called HwAudKiller. The attackers employ stacked cloaking services (Adspect and JustCloakIt) and a legitimately signed Huawei driver (HWAuidoOs2Ec.sys) to blind EDRs, enable LSASS...
www.hendryadrian.com
March 25, 2026 at 1:00 PM
Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam
Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam
A malware campaign presents fake websites that can check if a visitor is a potential victim or a security researcher, and then proceed accordingly to defraud or evade.
www.darkreading.com
November 18, 2025 at 5:34 PM
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages
thehackernews.com
November 18, 2025 at 12:49 PM
Malicious NPM packages abuse Adspect redirects to evade security
Malicious NPM packages abuse Adspect redirects to evade security
Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations.
www.bleepingcomputer.com
November 18, 2025 at 12:04 AM
Cybersecurity researchers reveal 7 npm packages exposed by a single attacker targeting cryptocurrency users

Cybersecurity researchers have uncovered a set of seven npm packages published by a single attacker. These packages use a cloaking service called Adspect to distinguish between real victims…
Cybersecurity researchers reveal 7 npm packages exposed by a single attacker targeting cryptocurrency users
Cybersecurity researchers have uncovered a set of seven npm packages published by a single attacker. These packages use a cloaking service called Adspect to distinguish between real victims and security researchers, and ultimately redirect to sketchy crypto-themed sites. Malicious npm packages were published by a threat actor named 'dino_reborn' between September and November 2025. Packages include signals-embed (342 downloads), dsidospsodlks (184 downloads), applicationooks21 (340 downloads), application-phskck (199 downloads), integrator-filescrypt2025 (199 downloads), integrator-2829 (276 downloads).
earlybirdsinvest.com
November 19, 2025 at 3:13 AM
📢 Campagne npm malveillante: cloaking Adspect et faux CAPTCHAs pour rediriger vers des arnaques crypto
📝 Source: Socket (Socket Threat Resea…
https://cyberveille.ch/posts/2025-11-22-campagne-npm-malveillante-cloaking-adspect-et-faux-captchas-pour-rediriger-vers-des-arnaques-crypto/ #IOC #Cyberveille
November 22, 2025 at 5:00 PM
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 72

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Contagious Interview Actors Now Utilize JSON Storage Services for Malware Del…
#gpt #hackernews #news
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 72
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Contagious Interview Actors Now Utilize JSON Storage Services for Malware Delivery RONINGLOADER: DragonBreath’s New Path to PPL Abuse   npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects  GPT Trade: Fake Google Play Store […]
securityaffairs.com
November 24, 2025 at 1:41 PM
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages

Cybersecurity researchers have discovered a set of seven npm packages published by a single threat actor that leverages a cloaking service called Adspect to differentiate between real victims and secu…
#hackernews #news
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages
Cybersecurity researchers have discovered a set of seven npm packages published by a single threat actor that leverages a cloaking service called Adspect to differentiate between real victims and security researchers to ultimately redirect them to sketchy crypto-themed sites. The malicious npm packages, published by a threat actor named "dino_reborn" between September and November 2025, are
thehackernews.com
November 19, 2025 at 3:24 PM
Malicious NPM packages abuse Adspect redirects to evade security

Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations. [...]
#hackernews #news
Malicious NPM packages abuse Adspect redirects to evade security
Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations. [...]
www.bleepingcomputer.com
November 19, 2025 at 1:33 AM
npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects https://socket.dev/blog/npm-malware-campaign-uses-adspect-cloaking-to-deliver-malicious-redirects
npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects
npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects
socket.dev
November 19, 2025 at 3:20 AM
The Hidden Trap Inside npm: How a Single Threat Actor Used Adspect Cloaking to Target Crypto Victims

Introduction to a Silent Supply Chain Threat A wave of malicious npm packages has exposed a troubling evolution in JavaScript‑based supply chain attacks. Researchers uncovered seven packages tied…
The Hidden Trap Inside npm: How a Single Threat Actor Used Adspect Cloaking to Target Crypto Victims
Introduction to a Silent Supply Chain Threat A wave of malicious npm packages has exposed a troubling evolution in JavaScript‑based supply chain attacks. Researchers uncovered seven packages tied to a single threat actor who used a professional-grade cloaking service, Adspect, to selectively target victims while hiding from cybersecurity analysts. This discovery highlights how attackers are now merging ad‑tech cloaking, browser fingerprinting, and open‑source ecosystems into one coordinated operation.
undercodenews.com
November 18, 2025 at 10:55 AM
Malicious npm Packages Exploit Adspect to Funnel Users Into Crypto Scams

🎯 Introduction A wave of malicious activity has emerged on the Node Package Manager (npm) registry, where seemingly innocent packages are being used to funnel unsuspecting users toward cryptocurrency scams. Researchers have…
Malicious npm Packages Exploit Adspect to Funnel Users Into Crypto Scams
🎯 Introduction A wave of malicious activity has emerged on the Node Package Manager (npm) registry, where seemingly innocent packages are being used to funnel unsuspecting users toward cryptocurrency scams. Researchers have identified seven npm packages that exploit the Adspect cloud-based service to distinguish between security researchers and real victims, redirecting the latter to fraudulent cryptocurrency webpages. This attack highlights the growing sophistication of supply chain threats in the JavaScript ecosystem, targeting both developers and end users.
undercodenews.com
November 18, 2025 at 12:20 AM