Briefing

148 npm Packages Turn Browsers into DDoS Botnet via Student Proxy Scam

security
by [email protected] (The Hacker News) ·

Remove the compromised npm packages and audit your dependencies to prevent botnet infection.

What to do now

Remove the compromised packages, run npm audit, and replace them with trusted alternatives.

Summary

An attack campaign used 148 npm packages disguised as student web proxies to turn visitors' browsers into a distributed denial‑of‑service botnet for roughly two weeks in May. The malicious packages were hosted on the npm registry and leveraged a booby‑trapped proxy site that redirected traffic to the attackers' infrastructure. When users installed the packages, their browsers silently became part of a botnet that sent massive traffic bursts to target sites, yet the developers who installed the packages were not the intended victims. The operators exploited the npm registry as free hosting, avoiding direct contact with developers. The botnet operated for about 14 days before the packages were removed from the registry. Security researchers recommend auditing dependencies and removing any suspicious packages. The incident underscores the risk of trusting third‑party npm modules that provide proxy functionality. No direct exploitation of the packages themselves was required; the threat came from the proxy behavior embedded in them.

Key changes

  • 148 npm packages disguised as student web proxies
  • Packages turned browsers into a DDoS botnet for ~2 weeks in May
  • Attackers used npm registry as free hosting for a booby‑trapped proxy site
  • Developers installing the packages were not targeted; the browsers were
  • Botnet sent massive traffic bursts to target sites
  • Security researchers recommend auditing dependencies and removing suspicious packages

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting