148 npm Packages Disguised as Student Proxies Turned Browsers Into a… | HappeningNow.news

Cybersecurity · 30 views

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.

Source AI Summary Published July 14, 2026 Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 30 Community interest
Brief read Under 1 min brief 101 words

AI Summary

Researchers have identified 148 npm packages that masqueraded as student web proxies, but instead turned browsers into a distributed denial-of-service (DDoS) botnet for approximately two weeks in May. These packages, which were hosted on the npm registry, did not target the developers who installed them. Instead, the operators used the registry as a free hosting platform for a compromised proxy site, which then infected visitors' browsers and turned them into a botnet. The significance of this development lies in the fact that it highlights the potential for malicious actors to exploit open-source package repositories, such as npm, for their own purposes.

AI summaries can be wrong sometimes—always verify important details using the source article.

How AI & Automation are used
Read original at The Hackernews

Coverage Context

Part of Ddos coverage 20 tracked stories

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page