Skip to content

148 npm Packages Disguised as Student Proxies – Browsers Turned into DDoS Bots

The gist: 148 npm packages were abused as student proxies to turn browser visitors into DDoS attack bots, without developers being the primary targets.

Researchers at JFrog have discovered 148 manipulated npm packages that were presented as web proxies for students and turned visitor browsers into a distributed denial-of-service botnet for roughly two weeks in May.

The campaign did not primarily target developers who would install the packages. Instead, the attackers used the npm registry as free hosting infrastructure for a prepared proxy website and targeted students who used it to bypass school network blocks.

For CTOs, this discovery presents a dual security risk: on one hand, it once again demonstrates the vulnerability of central package repositories to supply chain attacks. On the other hand, browser-based botnet architectures are revealed as practically implementable without the end user possessing technical knowledge – a vector that is easily scalable through popular academic proxies.

JFrog reported the packages to the npm registry and they were removed. The long-term implications remain unclear: whether the DDoS traffic volumes generated over two weeks can be traced back, which targets were attacked, and whether malicious actors will reuse this infrastructure for further campaigns requires further investigation.

Organizations are advised to conduct thorough reviews of dependencies in npm projects and implement Software Composition Analysis (SCA) tools to detect similar suspicious packages early on.


Source: thehackernews.com · Published 14 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.

Share on: