Researchers reported a campaign involving 148 npm packages that masqueraded as student proxy, school Wi-Fi bypass, and tutoring tools while secretly turning visitors’ browsers into a browser-based DDoS botnet. The packages, tied to Lucide Proxy branding and related names such as Riverbend Tutoring and Northstar Tutoring, were used mainly to host proxy web pages rather than infect developers during npm install. JFrog and SafeDep found the operation evolved from adware and tracking activity into active traffic-flooding behavior, with hidden scripts, service workers, and obfuscated JavaScript loading mutable second-stage code from remote infrastructure.
Archived payloads showed one module sending repeated large POST requests at cdn.caan.edu, while another opened rapid WebSocket connections against a Wisp-compatible endpoint at lunaron[.]top. Researchers linked much of the infrastructure to a lucideproxy GitHub organization and a G-Core Labs-hosted IP, 92.38.177[.]17, and said the attackers removed overt DDoS modules on May 31 while preserving the ability to restore them through a remote branch; a later wave on July 8 expanded the package count. Many packages were removed from npm, but some malicious versions reportedly remained available, and defenders were urged to review browser telemetry, DNS and web-filtering logs, clear affected browsers’ site data and service workers, and rotate credentials used through the proxy pages.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
SafeDep first documented 141 related npm packages in May, describing them as abuse tied to adware-hosting proxy pages masquerading as student-focused services.
JFrog reported that the operation shifted from adware to active browser-based DDoS behavior in mid-May, using remote JavaScript and traffic-flooding modules loaded by the hosted proxy pages.
JFrog said the npm package campaign initially operated as adware in March before later evolving into browser-based DDoS functionality.
As of 2026-07-14, many packages had been removed from npm, but JFrog said at least some malicious versions were still available.
JFrog said a later wave began on 2026-07-08, increasing the total number of identified npm packages in the campaign to 148.
On 2026-05-31, the campaign removed overt malicious modules from the npm packages as scrutiny increased, while retaining the ability to re-enable malicious behavior through mutable remote code.
JFrog said the first wave of the campaign began on 2026-05-27, tied to Lucide Proxy branding and packages that served proxy-site assets while exposing visitors to malicious second-stage code.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 47 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
5 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcecybersecuritynews.com
Open sourcetrojan-killer.net
Open sourcethehackernews.com
Open sourceresearch.jfrog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.