148 npm Packages Pose as Student Proxies, Turn Browsers into DDoS Botnet
Researchers discovered 148 malicious npm packages disguised as student proxy tools. When installed, they hijack browsers to form a distributed denial-of-service (DDoS) botnet. This campaign exposes the risk of supply chain attacks targeting developers and students.