dino_reborn is the online persona associated with a malicious npm supply-chain campaign that distributed browser-executed packages designed to facilitate cryptocurrency scams. The actor published seven npm packages that embedded cloaking and anti-analysis logic, using the Adspect traffic-filtering service through attacker-controlled proxy infrastructure to distinguish likely victims from security researchers and automated inspection systems. The packages collected detailed client fingerprinting data, including browser and device characteristics, locale, referrer context, and network-derived attributes, then used that information to determine whether to present scam content, benign decoy content, or a blank page. The campaign relied on automatic execution of malicious JavaScript in the browser, social-engineering users with fake CAPTCHA flows and delayed redirects to cryptocurrency-themed scam pages impersonating or referencing legitimate decentralized-exchange brands. This design supported rapid rotation of downstream scam destinations while reducing exposure in static analysis. Anti-analysis behavior included interference with developer-tool usage and other measures intended to frustrate inspection. When traffic was classified as unwanted, such as from researchers, the actor could redirect users to a polished decoy company site to reduce suspicion and increase analyst dwell time. The activity is best characterized as financially motivated open-source ecosystem abuse focused on cryptocurrency theft. High-confidence reporting directly ties the campaign to the dino_reborn npm user profile, but there is no corroborated attribution to a known nation-state or broader intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The threat actor 'dino_reborn' published seven malicious npm packages that use the Adspect cloud-based service to conduct cryptocurrency scams. The packages employ cloaking and anti-analysis techniques to evade detection and redirect users to fake CAPTCHA pages with cryptocurrency branding.
Operates a malicious npm supply-chain campaign using browser-executed JavaScript to fingerprint visitors, route telemetry through an attacker-controlled proxy to Adspect cloaking infrastructure, and selectively redirect likely victims to cryptocurrency-themed scam sites while showing researchers benign/decoy content (e.g., a blank page or a fake company site) to evade analysis.
Publishing malicious NPM packages that use Russian cloaking technology to target users of crypto platforms Uniswap and StandX. The campaign uses advanced evasion techniques and is likely part of a testing phase for a larger campaign, possibly targeting crypto developers via phishing or watering hole attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.