CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2465

As cited

Copy frozen at (site build).

threat intel

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

Researchers at JFrog discovered 148 malicious npm packages disguised as student web proxies that redirected visitors' browsers into a DDoS botnet during May. The campaign targeted end users visiting the proxy sites rather than the developers who installed the packages, leveraging npm's registry as free hosting for the malicious infrastructure.

Why it matters: Developers relying on npm packages must validate package legitimacy and watch for supply chain attacks that abuse trusted registries; organizations should monitor outbound traffic from developer machines for unexpected botnet activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

Researchers identified 148 npm packages that posed as student web proxies and hijacked visitors browsers to launch a distributed denial of service attack. The campaign operated for about two weeks in May, using the registry as free hosting for the booby trapped site. No developers were targeted directly; instead the packages served as a trap for students seeking to bypass network restrictions.

Why it matters: Developers who install npm packages are affected, as these malicious proxies can turn end users browsers into DDoS bots, so practitioners should review and remove any suspicious packages from their projects.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary