Cybersecurity · 30 views
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.
AI Summary
Researchers have identified 148 npm packages that masqueraded as student web proxies, but instead turned browsers into a distributed denial-of-service (DDoS) botnet for approximately two weeks in May. These packages, which were hosted on the npm registry, did not target the developers who installed them. Instead, the operators used the registry as a free hosting platform for a compromised proxy site, which then infected visitors' browsers and turned them into a botnet. The significance of this development lies in the fact that it highlights the potential for malicious actors to exploit open-source package repositories, such as npm, for their own purposes.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- Surfshark Systems Targeted by HackersContinue reading
- Microsoft fixes Teams, Outlook launch failures on ARM Windows PCsContinue reading
- Anthropic Says Russian Hackers Used Claude AI to Automate Malware EvasionContinue reading
- Trezor: 347,000 users targeted in phishing attacks after Brevo breachContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow