
The Hacker News
July 14, 20261 min read
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog. The packages did not go after the developers who might install them. The operators used the registry as free hosting for a booby-trapped proxy site and let the students who came to dodge
Read what's here, then head to the original whenever you're ready - never required.
Continue Reading on The Hacker NewsNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
The Hacker News July 21, 2026