A new student proxy botnet campaign abused fake npm packages to launch hidden cyberattacks. The packages appeared to offer web proxy services for students. However, they secretly turned visitors’ browsers into attack tools. As a result, users joined a distributed denial-of-service attack without knowing it. Therefore, the campaign exposed both students and organizations to serious security risks.
Fake Proxy Packages Hide Malicious Code
Researchers discovered 148 malicious npm packages during the investigation. The packages looked like harmless student proxy applications. Therefore, users believed they only bypassed internet restrictions. The proxy service worked as expected on the surface. However, hidden code executed in the background after each browser session began.
Unlike traditional malicious packages, these files did not attack developers. Instead, they targeted anyone who opened the hosted proxy website. As a result, every visitor unknowingly became part of the attack. The packages contained no installation scripts or build hooks. Therefore, many security tools failed to detect the threat.
Browsers Secretly Joined DDoS Attacks
The hidden code downloaded additional scripts from remote servers. Therefore, attackers could change the malicious behavior at any time. The scripts generated a large number of network requests. As a result, each browser sent continuous traffic toward selected targets. Users never received any warning during the process.
Researchers also found a second attack module. This feature created multiple WebSocket connections to remote servers. For example, one browser could open dozens of simultaneous connections. Therefore, attackers overwhelmed targeted systems with constant connection requests. This activity placed heavy pressure on affected infrastructure.
Attackers Controlled the Campaign Remotely
Researchers explained that the remote loader lacked basic security protections. Therefore, attackers could replace the downloaded code whenever they wanted. The browser automatically executed every updated script. As a result, the campaign remained flexible without releasing new package versions. This design made the threat especially dangerous.
The attackers also hid their activity through remote hosting services. Furthermore, they used changing scripts instead of permanent malware. Therefore, security teams faced greater challenges during detection. Researchers traced most campaign infrastructure to closely related online accounts. However, the operators later removed several malicious components.
Researchers Reconstructed the Attack
Researchers recovered archived files to rebuild the attack timeline. They discovered that the campaign began as adware. However, the operators later added DDoS capabilities. Therefore, the threat became much more damaging over time. Investigators also found evidence that attackers could reactivate the malicious features whenever they wanted.
Many malicious packages have already disappeared from public repositories. However, several dangerous versions remained available during the investigation. Therefore, users could still download affected packages. Researchers warned that public software repositories remain attractive attack platforms. Organizations should monitor package sources carefully.
Why This Campaign Matters
The attack shows how browser-based threats continue evolving. Instead of infecting developer systems, attackers abused ordinary web users. Therefore, traditional package security checks missed much of the malicious behavior. The browser became the attack platform instead of the installation process. This shift creates new challenges for cybersecurity teams.
Researchers also warned that attackers can quickly restore hidden functions. For example, they only need to update remotely hosted scripts. Therefore, dangerous behavior can return without publishing new software packages. Organizations should continuously monitor external resources. Strong browser security policies also reduce exposure.
How to Prevent Student Proxy Botnet Attacks
Organizations should block untrusted proxy websites and monitor browser traffic for unusual outbound connections. They should also educate users about the risks of unofficial proxy services and suspicious software repositories. Furthermore, managed endpoint detection and response services can identify hidden browser-based attacks before they spread across the network.
In addition, continuous security monitoring and threat hunting services help detect suspicious activity early, reducing the risk of DDoS participation and malicious remote code execution.
Sleep well, we got you covered.

