148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
ID: f8c79f3c-ed38-5ac5-aa84-4d38585e9d97
STIX ID: report--f8c79f3c-ed38-5ac5-aa84-4d38585e9d97
Feed Name: The Hacker News
A campaign of 148 malicious npm packages disguised as student web proxies (branded Lucide / tutoring landing pages) loaded a remote script loader (G2) and a WebSocket flood generator (I2) in visitors' browsers, weaponizing open tabs into a DDoS botnet. The G2 module fetched mutable JavaScript from a GitHub branch and executed it with page origin privileges to run an HTTP flood, while I2 opened many Wisp WebSocket connections and repeatedly sent CONNECT/CLOSE frames to exhaust remote proxy servers' resources and logs. JFrog deobfuscated the single-file bundles, reconstructed archived payloads, identified hosting and repository infrastructure, and recommended DNS/domain blocking, clearing browser caches/service workers, and removing the packages from manifests and lockfiles.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
