hacker-news · Crawled Jul 14, 2026

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

7 IoCs
Read original article ↗

AI Summary

A cyber threat campaign distributed 148 malicious npm packages disguised as student web proxies, which when accessed via browser turned devices into a DDoS botnet. The packages hosted a proxy application named 'Lucide' that appeared legitimate but silently loaded remote code and executed WebSocket-based attacks. The malicious infrastructure leveraged GitHub repositories and CDNs to deliver payloads, targeting a nursing school's domain and Wisp proxy servers. The operators maintained persistent control through mutable branches and could re-enable DDoS capabilities at any time.

AI-extracted · verify before operational use

Indicators of Compromise 7 extracted

Type Value Detail
Domain cdn[.]caan[.]edu Details →
Domain lunaron[[.]]top Details →
Domain woofbeginner[[.]]com Details →
Domain c[.]vipersfutbol[[.]]com Details →
IP 92[.]38[.]177[.]17 Details →
GitHub Repo lucideproxy Details →
Registry User geeked[.]wtf Details →