Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations. The purpose of the attack is to lead victims to cryptocurrency scam sites, according to an analysis from researchers at application security company Socket. All malicious packages were published under the developer namee ‘dino_reborn’ (geneboo@proton[.]me) between September and November. However, six of them contain malicious code while the seventh is used to build a malicous webpage: The researchers say that signals-embed is not inherently malicious and contains only the code to create a white decoy webpage. The other six have code that collects data about the visitors to determine if the traffic comes from a researcher or from a potential victim. This is achieved by collecting information from the browser environment, such as browser identifiers, page and URL data, host and hostname of the current page, and prepares it for sending to Adspect’s API. The six malicious packages contain a 39kB code that features the cloaking mechanism, Socket researchers note, adding that the code executes automatically on page load without extra user action, due to Immediately Invoked Function Expression (IIFE) wrapping. The attack executes when the compromised developer’s web application loads the malicious JavaScript in a browser. According to Socket, the injected code features anti-analysis such as block...
Malicious NPM packages abuse Adspect redirects to evade security
BleepingComputer
·Bill Toulas
·Published Nov 17, 2025
·Updated
Affected Software
1 affected component
npm package
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses malicious NPM packages that misuse Adspect redirects to avoid detection by security researchers.
2
What security implications are discussed in the article?
The article highlights how attackers use sophisticated techniques to evade security measures and target unsuspecting victims.
3
What products or software are affected by these malicious NPM packages?
The affected software includes seven malicious packages published on the Node Package Manager (npm) registry.
4
What method is used by these malicious packages to mislead researchers?
The malicious packages utilize the Adspect cloud-based service to redirect potential victims away from security scrutiny.
5
What is the ultimate goal of the attackers using these NPM packages?
The ultimate goal of the attackers is to direct victims to malicious locations through deceptive redirects.