Dino_reborn npm malware campaign with Adspect cloaking
Campaign
Summary
Hide ▲
Show ▼
dino_reborn ran a coordinated npm malware campaign that used seven packages, Adspect API cloaking, and fake crypto-exchange CAPTCHAs to route visitors toward malicious redirects. The code fingerprinted visitors with 13 data points and split them into a researcher path or a victim path, reducing visibility into the operation. The packages were later placed into security holding after takedown requests.
Related Happenings
PromptMink malicious npm dependency stealing secrets and crypto wallets
Malware Activity
First: 29.04.2026 17:00
Last: 29.04.2026 17:00
Sources 1
About this happening:
The **PromptMink** malicious npm dependency now poses an immediate theft risk because it is stealing sensitive data and exposing **crypto wallets** from infected environments. The...
PromptMink malicious npm dependency stealing secrets and crypto wallets
Malware ActivityAbout this happening: The **PromptMink** malicious npm dependency now poses an immediate theft risk because it is stealing sensitive data and exposing **crypto wallets** from infected environments. The...
Ghost campaign malicious npm supply-chain operation
Campaign
First: 24.03.2026 16:30
Last: 24.03.2026 16:30
Sources 1
About this happening:
A **malicious npm supply-chain campaign** dubbed **"Ghost campaign"** is using **fake installation logs** to conceal malware delivery, increasing the chance that package installer...
Ghost campaign malicious npm supply-chain operation
CampaignAbout this happening: A **malicious npm supply-chain campaign** dubbed **"Ghost campaign"** is using **fake installation logs** to conceal malware delivery, increasing the chance that package installer...
Ghost campaign remote access trojan payload
Malware Activity
First: 24.03.2026 16:30
Last: 24.03.2026 16:30
Sources 1
About this happening:
A malicious **npm** payload tied to the **Ghost campaign** began in **early February** and used **fake installation logs** to hide a **remote access trojan (RAT)** that could stea...
Ghost campaign remote access trojan payload
Malware ActivityAbout this happening: A malicious **npm** payload tied to the **Ghost campaign** began in **early February** and used **fake installation logs** to hide a **remote access trojan (RAT)** that could stea...
Ghost campaign malicious npm package operation
Campaign
First: 24.03.2026 14:00
Last: 24.03.2026 14:00
Sources 1
About this happening:
The **Ghost campaign** is pushing **malicious npm packages** that steal **sudo/root credentials** and enable wallet-targeting payloads, raising risk for developers using the **Nod...
Ghost campaign malicious npm package operation
CampaignAbout this happening: The **Ghost campaign** is pushing **malicious npm packages** that steal **sudo/root credentials** and enable wallet-targeting payloads, raising risk for developers using the **Nod...
CanisterWorm self-propagation across npm packages
Malware Activity
First: 21.03.2026 09:28
Last: 21.03.2026 09:28
Sources 1
About this happening:
A **self-propagating npm supply-chain worm** tracked as **CanisterSprawl** is abusing **stolen developer npm tokens** to spread through compromised packages. **Socket** and **Step...
CanisterWorm self-propagation across npm packages
Malware ActivityAbout this happening: A **self-propagating npm supply-chain worm** tracked as **CanisterSprawl** is abusing **stolen developer npm tokens** to spread through compromised packages. **Socket** and **Step...
Timeline
-
18.11.2025 18:00 2 articles · 6mo ago
Socket uncovers dino_reborn npm malware campaign
Initial DisclosureThe Socket Threat Research Team uncovered a dino_reborn campaign built around seven npm packages, including signals-embed, dsidospsodlks, applicationooks21, application-phskck, integrator-filescrypt2025, integrator-2829 and integrator-2830. The packages executed automatically, fingerprinted visitors with 13 data points, forwarded them through Adspect API cloaking, showed a white page to suspected researchers, and presented fake CAPTCHAs branded standx.com, jup.ag or uniswap.org to potential victims before redirecting them to malicious URLs. Takedown requests later placed all seven packages into security holding.
Show sources
- New npm Malware Campaign Redirects Victims to Crypto Sites — www.infosecurity-magazine.com — 18.11.2025 18:00
- New npm Malware Campaign Redirects Victims to Crypto Sites — www.infosecurity-magazine.com — 18.11.2025 18:00