VMTech
Discuss a project

148 npm‑пакетов маскировались под студенческие прокси и превращали браузеры в DDoS‑ботнет

148 npm‑пакетов маскировались под студенческие прокси и превращали браузеры в DDoS‑ботнет

Colleagues, I’d like to draw attention to a cybersecurity case. JFrog reported on 148 npm packages that posed as student proxy services and quietly turned visitors’ browsers into a DDoS botnet.

What matters:
- the code did not run at installation; it executed directly in the browser;
- it used a remote loader and WebSocket flooding;
- outwardly, it looked like a normal proxy page for bypassing filters.

Why it matters: schemes like this evade standard checks and impact both users and infrastructure at the same time.

Do you think browser-based proxies have already become a distinct threat class?

#Cybersecurity #npm #DDoS #OpenSourceSecurity

Open analytics
On the site 5 views
min read 1 14.07.2026
On Instagram 4 views
On Instagram 1 reach
Instagram

148 npm‑пакетов маскировались под студенческие прокси и превращали браузеры в DDoS‑ботнет

Open the post on Instagram ↗