A threat actor identified as 'dino_reborn' published seven packages to the npm registry, six of which contain malicious JavaScript designed to redirect victims to cryptocurrency scam sites. These packages leverage the Adspect cloud-based service to implement cloaking techniques, distinguishing between regular users and security researchers by collecting browser and environment data. If a visitor is identified as a potential victim, they are shown a fake CAPTCHA and ultimately redirected to a malicious site, while researchers are served a decoy page to evade detection. The packages involved are: signals-embed, dsidospsodlks, applicationooks21, application-phskck, integrator-filescrypt2025, integrator-2829, and integrator-2830, with only signals-embed acting as a decoy and the rest containing the 39kB malicious payload.
The malicious code is automatically executed in the browser via an Immediately Invoked Function Expression (IIFE) and includes anti-analysis features such as blocking right-click, F12, and other developer tools shortcuts, as well as reloading the page if DevTools is detected. The Socket Threat Research Team discovered the campaign and submitted takedown requests, resulting in npm placing the packages in security holding. The attack highlights the increasing sophistication of supply chain threats in open-source ecosystems, particularly through the use of advanced cloaking and anti-analysis techniques to evade detection and target end users.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Following the discovery, Socket notified npm about the malicious packages. The identified packages were then removed from the npm registry.
Socket Threat Research publicly reported the supply-chain campaign, detailing the use of cloaking, anti-analysis techniques, visitor fingerprinting, and delayed redirects to scam infrastructure. Multiple outlets subsequently covered the same disclosure.
Researchers observed the packages using Adspect through an attacker-controlled proxy to decide whether to redirect users to fake CAPTCHA pages and crypto-themed scam sites or show benign decoy content. The lures referenced brands such as StandX, Jupiter, and Uniswap, while suspected researchers could be sent to a fake 'Offlido' company site.
An actor using the npm profile 'dino_reborn' published seven malicious packages that embedded browser-executed code. The packages were designed to fingerprint visitors, evade analysis, and support cryptocurrency scam redirections.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcegetsafety.com
Open sourcescworld.com
Open sourcedarkreading.com
Open sourcesocket.dev
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.