• bitcoinBitcoin (BTC) $ 89,909.00
  • ethereumEthereum (ETH) $ 3,100.98
  • tetherTether (USDT) $ 0.999546
  • xrpXRP (XRP) $ 2.00
  • bnbBNB (BNB) $ 874.85
  • usd-coinUSDC (USDC) $ 0.999997
  • staked-etherLido Staked Ether (STETH) $ 3,096.71
  • tronTRON (TRX) $ 0.288656
  • dogecoinDogecoin (DOGE) $ 0.142848
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • cardanoCardano (ADA) $ 0.385723
  • bitcoin-cashBitcoin Cash (BCH) $ 636.03
  • whitebitWhiteBIT Coin (WBT) $ 57.02
  • wrapped-stethWrapped stETH (WSTETH) $ 3,795.31
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 89,686.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,371.53
  • usdsUSDS (USDS) $ 0.999618
  • wrapped-eethWrapped eETH (WEETH) $ 3,364.12
  • chainlinkChainlink (LINK) $ 13.12
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999245
  • leo-tokenLEO Token (LEO) $ 9.23
  • zcashZcash (ZEC) $ 510.72
  • wethWETH (WETH) $ 3,100.61
  • moneroMonero (XMR) $ 430.68
  • stellarStellar (XLM) $ 0.218981
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 89,838.00
  • ethena-usdeEthena USDe (USDE) $ 0.999885
  • litecoinLitecoin (LTC) $ 81.49
  • suiSui (SUI) $ 1.63
  • avalanche-2Avalanche (AVAX) $ 14.21
  • hyperliquidHyperliquid (HYPE) $ 24.44
  • canton-networkCanton (CC) $ 0.153087
  • hedera-hashgraphHedera (HBAR) $ 0.118588
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • susdssUSDS (SUSDS) $ 1.08
  • usdt0USDT0 (USDT0) $ 0.999721
  • the-open-networkToncoin (TON) $ 1.80
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.157062
  • daiDai (DAI) $ 0.999787
  • crypto-com-chainCronos (CRO) $ 0.098761
  • uniswapUniswap (UNI) $ 5.82
  • paypal-usdPayPal USD (PYUSD) $ 0.999835
  • polkadotPolkadot (DOT) $ 2.12
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • mantleMantle (MNT) $ 0.989165
  • memecoreMemeCore (M) $ 1.67
  • rainRain (RAIN) $ 0.008009
  • pepePepe (PEPE) $ 0.000006
  • bitget-tokenBitget Token (BGB) $ 3.52
  • aaveAave (AAVE) $ 159.05
  • bittensorBittensor (TAO) $ 244.83
  • okbOKB (OKB) $ 111.85
  • tether-goldTether Gold (XAUT) $ 4,353.32
  • nearNEAR Protocol (NEAR) $ 1.69
  • falcon-financeFalcon USD (USDF) $ 0.997870
  • ethereum-classicEthereum Classic (ETC) $ 12.42
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,099.91
  • jito-staked-solJito Staked SOL (JITOSOL) $ 163.62
  • ethenaEthena (ENA) $ 0.233367
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • aster-2Aster (ASTER) $ 0.735417
  • pi-networkPi Network (PI) $ 0.208431
  • internet-computerInternet Computer (ICP) $ 3.12
  • hash-2Provenance Blockchain (HASH) $ 0.031641
  • pax-goldPAX Gold (PAXG) $ 4,369.90
  • solanaWrapped SOL (SOL) $ 130.72
  • midnight-3Midnight (NIGHT) $ 0.094337
  • htx-daoHTX DAO (HTX) $ 0.000002
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • worldcoin-wldWorldcoin (WLD) $ 0.576474
  • global-dollarGlobal Dollar (USDG) $ 0.999688
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.64
  • kucoin-sharesKuCoin (KCS) $ 10.97
  • aptosAptos (APT) $ 1.88
  • binance-staked-solBinance Staked SOL (BNSOL) $ 142.81
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • skySky (SKY) $ 0.059989
  • ripple-usdRipple USD (RLUSD) $ 0.999580
  • bfusdBFUSD (BFUSD) $ 0.999123
  • ondo-financeOndo (ONDO) $ 0.417322
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999746
  • pump-funPump.fun (PUMP) $ 0.002195
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,577.74
  • myx-financeMYX Finance (MYX) $ 6.73
  • wbnbWrapped BNB (WBNB) $ 874.68
  • gatechain-tokenGate (GT) $ 10.48
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.113679
  • kaspaKaspa (KAS) $ 0.044644
  • arbitrumArbitrum (ARB) $ 0.206385
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,289.39
  • algorandAlgorand (ALGO) $ 0.126162
  • cosmosCosmos Hub (ATOM) $ 2.23
  • filecoinFilecoin (FIL) $ 1.47
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • bridged-wrapped-lido-staked-ether-scrollBridged Wrapped Lido Staked Ether (Scroll) (WSTETH) $ 3,783.61
  • xdce-crowd-saleXDC Network (XDC) $ 0.053364
  • official-trumpOfficial Trump (TRUMP) $ 5.03
  • vechainVeChain (VET) $ 0.011626
  • ignition-fbtcFunction FBTC (FBTC) $ 90,113.00
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 89,901.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 89,373.00
  • nexoNEXO (NEXO) $ 0.932496
  • flare-networksFlare (FLR) $ 0.010913
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,306.71
  • usddUSDD (USDD) $ 0.999664
  • usdtbUSDtb (USDTB) $ 0.999418
  • ousgOUSG (OUSG) $ 113.85
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.94
  • render-tokenRender (RENDER) $ 1.52
  • bonkBonk (BONK) $ 0.000009
  • sei-networkSei (SEI) $ 0.120925
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999965
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999701
  • story-2Story (IP) $ 2.12
  • beldexBeldex (BDX) $ 0.094821
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 89,794.00
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,363.98
  • clbtcclBTC (CLBTC) $ 91,138.00
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,311.08
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010622
  • lighterLighter (LIT) $ 2.65
  • jupiter-exchange-solanaJupiter (JUP) $ 0.206262
  • usdaiUSDai (USDAI) $ 1.00
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,266.51
  • wrapped-flareWrapped Flare (WFLR) $ 0.010924
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 1.00
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 151.57
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,101.70
  • morphoMorpho (MORPHO) $ 1.13
  • optimismOptimism (OP) $ 0.305387
  • curve-dao-tokenCurve DAO (CRV) $ 0.403932
  • tezosTezos (XTZ) $ 0.534514
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.64
  • c8ntinuumc8ntinuum (CTM) $ 0.127084
  • blockstackStacks (STX) $ 0.302145
  • usual-usdUsual USD (USD0) $ 0.995957
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • dashDash (DASH) $ 43.03
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.819751
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.230748
  • tbtctBTC (TBTC) $ 89,565.00
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,103.56
  • lido-daoLido DAO (LDO) $ 0.607739
  • spx6900SPX6900 (SPX) $ 0.543707
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999898
  • ether-fiEther.fi (ETHFI) $ 0.762329
  • gtethGTETH (GTETH) $ 3,102.03
  • ghoGHO (GHO) $ 0.999219
  • true-usdTrueUSD (TUSD) $ 0.998555
  • injective-protocolInjective (INJ) $ 4.87
  • aerodrome-financeAerodrome Finance (AERO) $ 0.529769
  • fasttokenFasttoken (FTN) $ 1.09
  • chilizChiliz (CHZ) $ 0.044968
  • flokiFLOKI (FLOKI) $ 0.000047
  • stader-ethxStader ETHx (ETHX) $ 3,341.90
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,319.43
  • celestiaCelestia (TIA) $ 0.524042
  • msolMarinade Staked SOL (MSOL) $ 176.41
  • doublezeroDoubleZero (2Z) $ 0.128043
  • newton-projectAB (AB) $ 0.004518
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.213210
  • starknetStarknet (STRK) $ 0.084698
  • pippinpippin (PIPPIN) $ 0.430395
  • swethSwell Ethereum (SWETH) $ 3,440.42
  • syrupMaple Finance (SYRUP) $ 0.359553
  • sbtc-2sBTC (SBTC) $ 90,291.00
  • usdbUSDB (USDB) $ 0.989506
  • bittorrentBitTorrent (BTT) $ 0.00000040
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,471.55
  • iotaIOTA (IOTA) $ 0.093275
  • the-graphThe Graph (GRT) $ 0.036702
  • plasmaPlasma (XPL) $ 0.188684
  • conflux-tokenConflux (CFX) $ 0.075430
  • justJUST (JST) $ 0.039217
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.08
  • staked-aaveStaked Aave (STKAAVE) $ 158.84
  • telcoinTelcoin (TEL) $ 0.003946
  • sun-tokenSun Token (SUN) $ 0.019470
  • bitcoin-svBitcoin SV (BSV) $ 18.50
  • pendlePendle (PENDLE) $ 2.18
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.142700
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.875235
  • euro-coinEURC (EURC) $ 1.17
  • pyth-networkPyth Network (PYTH) $ 0.063252
  • gnosisGnosis (GNO) $ 136.09
  • olympusOlympus (OHM) $ 21.80
  • apenftAINFT (NFT) $ 0.00000036
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 89,907.00
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 17.65
  • kaiaKaia (KAIA) $ 0.058606
  • cap-usdCap USD (CUSD) $ 0.999740
  • crvusdcrvUSD (CRVUSD) $ 1.00
  • kinesis-goldKinesis Gold (KAU) $ 141.27
  • fartcoinFartcoin (FARTCOIN) $ 0.332793
  • basic-attention-tokenBasic Attention (BAT) $ 0.220462

Cybersecurity researchers reveal 7 npm packages published by a single threat actor targeting crypto users

0 39

Cybersecurity researchers reveal 7 npm packages published by a single threat actor targeting crypto users

Cybersecurity researchers have revealed a set of seven npm packages published by a single threat actor. These packages use a cloaking service called Adspect to distinguish between real victims and security researchers, ultimately redirecting them to sketchy, crypto-themed sites.

The malicious npm packages were published by a threat actor named “dino_reborn” between September and November 2025. The packages include signals-embed (342 downloads), dsidospsodlks (184 downloads), applicationooks21 (340 downloads), application-phskck (199 downloads), integrator-filescrypt2025 (199 downloads), integrator-2829 (276 downloads), and integrator-2830 (290 downloads).

Adspect poses as a cloud-based service that safeguards ad campaigns

According to its website, Adspect advertises a cloud-based service designed to protect ad campaigns from unwanted traffic, including click fraud and bots from antivirus companies. It also claims to offer “bulletproof cloaking” and that it “reliably cloaks each and every advertising platform.”

Cybersecurity researchers reveal 7 npm packages published by a single threat actor targeting crypto users

It offers three plans: Ant-Fraud, Personal, and Professional, which cost $299, $499, and $999 per month. The company also claims users can advertise “anything you want,” adding that it follows a no-questions-asked policy: we do not care what you run and do not enforce any content rules.”

Socket security researcher Olivia Brown stated, “Upon visiting a fake website constructed by one of the packages, the threat actor determines if the visitor is a victim or a security researcher […]If the visitor is a victim, they see a fake CAPTCHA, eventually bringing them to a malicious site. If they are a security researcher, only a few tells on the fake website would tip them off that something nefarious may be occurring.”

AdSpect’s ability to block researchers’ actions in its web browser

Out of these packages, six have a 39kB piece of malware that hides itself and makes a copy of the system’s fingerprint. It also attempts to evade analysis by blocking developer actions in a web browser, which prevents researchers from viewing the source code or launching developer tools.

The packages take advantage of a JavaScript feature called “Immediately Invoked Function Expression (IIFE).” It allows the malicious code to be executed immediately upon loading it in the web browser.

However, “signals-embed” does not have any malicious functionality outright and is designed to construct a decoy white page. The captured information is then sent to a proxy (“association-google[.]xyz/adspect-proxy[.]php”) to determine if the traffic source is from a victim or a researcher, and then serve a fake CAPTCHA.

After the victim clicks on the CAPTCHA checkbox, they are redirected to a bogus crypto-related page that impersonates services like StandX, with the likely goal of stealing digital assets. But if the visitors are flagged as potential researchers, a white fake page is displayed to the users. It also features HTML code related to the display privacy policy associated with a fake company named Offlido.

This report coincides with the Amazon Web Services report. It stated that its Amazon Inspector team identified and reported more than 150,000 packages linked to a coordinated TEA token farming campaign in the npm registry that has its origins in an initial wave that was detected in April 2024.

“This is one of the largest package flooding incidents in open source registry history, and represents a defining moment in supply chain security,” researchers Chi Tran and Charlie Bacon said. “Threat actors automatically generate and publish packages to earn cryptocurrency rewards without user awareness, revealing how the campaign has expanded exponentially since its initial identification.”

Source

Leave A Reply

Your email address will not be published.