logo

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

ID: f8c79f3c-ed38-5ac5-aa84-4d38585e9d97

STIX ID: report--f8c79f3c-ed38-5ac5-aa84-4d38585e9d97

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: [email protected] (The Hacker News)

...
...

A campaign of 148 malicious npm packages disguised as student web proxies (branded Lucide / tutoring landing pages) loaded a remote script loader (G2) and a WebSocket flood generator (I2) in visitors' browsers, weaponizing open tabs into a DDoS botnet. The G2 module fetched mutable JavaScript from a GitHub branch and executed it with page origin privileges to run an HTTP flood, while I2 opened many Wisp WebSocket connections and repeatedly sent CONNECT/CLOSE frames to exhaust remote proxy servers' resources and logs. JFrog deobfuscated the single-file bundles, reconstructed archived payloads, identified hosting and repository infrastructure, and recommended DNS/domain blocking, clearing browser caches/service workers, and removing the packages from manifests and lockfiles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.