Supply chain, Cloud Security, Threat Intelligence

Adspect cloaking exploited by npm packages for covert crypto scams

(Credit: Araki Illustrations – stock.adobe.com)

BleepingComputer reports that the Adspect cloud-based service has been weaponized by seven npm packages published by 'dino_reborn' to clandestinely facilitate cryptocurrency scams.

Half a dozen packages featured code with Adspect cloaking, which is automatically executed due to Immediately Invoked Function Expression wrapping, while the 'signals-embed' package contained code that enabled decoy webpage creation, according to a report from Socket. Included in the inherently nefarious packages' code were anti-analysis functions, such as Ctrl+U, Ctrl+Shift+I, and F12 blocking, as well as page reloading in the event of DevTools detection.

After obtaining visitors' details, including their user agents, URIs, hosts, referrers, and timestamps, the script fetches and forwards the IP address to Adspect API, with users then redirected to bogus CAPTCHA pages with cryptocurrency-related branding, said researchers, who noted that users identified to be researchers have been redirected to a phony but non-malicious Offlido company site.

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds