A large npm malware campaign, dubbed Lucide Proxy, deployed 148 packages designed to enlist visiting browsers into distributed denial-of-service (DDoS) browser botnets while generating pop-under advertising revenue. The packages contained covert remote code execution (RCE) vectors and a high-performance Wisp-compatible WebSocket traffic generator. Lucide Proxy Disguised as Student Tutoring Sites The campaign presented itself as […]
Package Count: JFrog uncovered 148 malicious npm packages, including ilovefemboys, miguelphonk, and charlie-kirk.
Attack Method: The packages disguised as student web proxies weaponized visitor browsers into DDoS botnets.
Active Window: The DDoS capabilities ran for roughly two weeks in May 2026 before reverting to adware.
A large npm malware campaign, dubbed Lucide Proxy, deployed 148 packages designed to enlist visiting browsers into distributed denial-of-service (DDoS) browser botnets while generating pop-under advertising revenue. The packages contained covert remote code execution (RCE) vectors and a high-performance Wisp-compatible WebSocket traffic generator.
Lucide Proxy Disguised as Student Tutoring SitesThe campaign presented itself as a web proxy application branded Lucide, disguised as tutoring landing pages named Riverbend Tutoring and Northstar Tutoring, JFrog reported on July 13, 2026, following a sandboxed local simulation. The proxy worked as advertised on the surface, allowing students to bypass school content filters to access games and blocked sites.
The first wave of packages was uploaded starting May 27, 2026, by the npm account iterminal3airporti, followed by a second wave on July 8, 2026, from the account ieerikakirki.
The Lucide Proxy website archived on May 18, 2026, during the period when the remote loader and Wisp traffic generator were present | Source: JFrogRather than using install hooks, the packages abused the npm registry as a free, high-bandwidth CDN to host static browser application assets. Malicious packages included:
Underneath the adware, the application loaded a mutable remote script from the GitHub account canyoupleasesaysomething, pointing to the changeable main branch with no Subresource Integrity (SRI) hash, meaning whoever controlled that GitHub account could alter the code running in every visitor's browser at will.
The CAAN Academy HTTP flood payload | Source: JFrogJFrog recovered a historical HTTP flood payload that issued unthrottled cross-origin POST requests every 500 milliseconds to the domain of the CAAN Academy of Nursing in Matteson, Illinois.
A Wisp-compatible WebSocket traffic generator could open up to 1,024 concurrent sockets per visitor, forcing target proxy servers to process over 10,000 socket allocations and connection attempts per second and corresponding socket destructions.
JFrog traced the infrastructure to a GitHub organization called lucideproxy, and found that 90 of 93 identified deployment hostnames resolved to a single IP address, hosted in AS199524 (G-Core Labs).
After public security reporting began in late May, the operators stripped the DDoS modules from the packages, reverting the builds to adware-only functionality. The report mentions that SafeDep flagged the same terminal3airport package wave earlier but classified it only as adware/registry spam.
Early this month, Google announced the disruption of NetNut, a 2-million-device residential proxy network tied to the Popa Botnet. NetNut is populated via SDKs distributed on home devices like smart TVs and streaming boxes, covertly enrolling them in the botnet as exit nodes.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Several npm repositories compromised | 0 | 5 | 01-06-2026 |
| 2 | Red Hat npm Package Compromise Highlights a Growing Supply Chain Problem | -2 | 7 | 02-06-2026 |
| 3 | Fake NVIDIA Software Distributes New LabubaRAT Malware to Hijack Windows PCs | 0 | 8 | 15-07-2026 |
| 4 | Специалисты Google нарушили работу сети резидентных прокси NetNut | 0 | 7 | 03-07-2026 |
| 5 | AryStinger: Why Thousands of Unpatched Linux Routers Are Being Weaponized | -2 | 7 | 22-06-2026 |
| 6 | Хакеры провели в 2025 году более 140 000 DDoS-атак на российские компании | 0 | 5 | 17-02-2026 |
| 7 | The hidden market turning home internet connections into cover for hackers | 0 | 8 | 25-06-2026 |
| 8 | Отечественные компании столкнулись с высокоорганизованной серией DDoS-атак | -1 | 6 | 30-06-2026 |
| 9 | Эксперты выявили 22 тысячи попыток заражения вредоносным ПО под видом сериалов Netflix | 0 | 0 | 21-07-2020 |
| 10 | Google при поддержке ФБР США вывела из строя часть инфраструктуры сети NetNut | 0 | 5 | 03-07-2026 |