148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

A recent investigation has uncovered that 148 npm packages masquerading as student web proxies were actually used to turn unsuspecting visitors' browsers into part of a DDoS botnet. These malicious packages were active for about two weeks in May, according to research from JFrog. This scheme highlights a significant security risk within the npm registry, where seemingly benign packages can be exploited for harmful purposes. The incident underscores the importance of rigorous security measures and vigilance in software package repositories.

Original Source

Read the full article at Thehackernews →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.