hacker-news · Crawled Jul 14, 2026
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
7 IoCs
Read original article ↗
AI Summary
A cyber threat campaign distributed 148 malicious npm packages disguised as student web proxies, which when accessed via browser turned devices into a DDoS botnet. The packages hosted a proxy application named 'Lucide' that appeared legitimate but silently loaded remote code and executed WebSocket-based attacks. The malicious infrastructure leveraged GitHub repositories and CDNs to deliver payloads, targeting a nursing school's domain and Wisp proxy servers. The operators maintained persistent control through mutable branches and could re-enable DDoS capabilities at any time.
AI-extracted · verify before operational use