148 npm Packages Disguised as Student Tutoring Proxies Turn Browsers Into DDoS Botnet (Lucide Proxy) — Threadlinqs Intelligence
As of 2026-07-14, 148 npm Packages Disguised as Student Tutoring Proxies Turn Browsers Into DDoS Botnet (Lucide Proxy) is a high-severity malware threat attributed to Unknown (lucideproxy, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-1304 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Unknown (lucideproxy · UNKNOWN
Between March and July 2026 the npm accounts 'terminal3airport' and a related follow-on account published 148 packages branded 'Lucide Proxy' and disguised as tutoring landing pages ('Riverbend
The Lucide Proxy campaign is npm-registry-as-CDN abuse layered with a covert browser-based DDoS botnet. The operators, assessed as a young/opportunistic actor rather than an APT, published 141 near-identical npm packages under the account 'terminal3airport' between May 7 and May 27, 2026 (package names such as changiairportpromax, ilovefemboys, backup1-gg through backup5-updated, ishowfeet1-20, nottuff1-30, abuden1-230), each shipping a byte-identical payload apart from package.json's name field. Every package's main entry point was a service worker (sw.js) implementing a web-proxy 'unblocker' built on the Mercury Workshop Scramjet proxy-rewriting engine and the Baremux transport library, relocated inside the tarball to obfuscated directory names (runtime/scramjet -> 8cfc2/, runtime/baremux -> d1g0y/). The service worker intercepted all fetch events on its origin, routed traffic through Scramjet's rewriting engine, and injected a script into every proxied HTML response that hooked window.open, anchor clicks, and form submissions to relay new-tab navigation to the parent frame via postMessage -- the injected flag window.open.__lucideIntercepted named the project. Branding assets referencing Anthropic, OpenAI, DeepSeek, xAI, Gemini, and Roblox indicate the sites specifically targeted students trying to reach AI chatbots and gaming sites from school networks. Monetization used popunder ads (cooldown 900,000ms / 15 minutes), third-party tracking scripts, and Google Analytics (G-0VL3ZSBXDH).
A second GitHub organization, lucideproxy (repo github.com/lucideproxy/svg), hosted a remote script loader referred to by JFrog as module 'G2'. G2 fetched JavaScript through the jsDelivr CDN pointed at the org's mutable main branch rather than a pinned commit, shipped with no Subresource Integrity hash, and executed the fetched code with the proxy site's own origin privileges -- full access to cookies, local storage, and same-origin endpoints. This let the operators swap the delivered payload at will without republishing to npm. In mid-May 2026 (~2-day burst) the operators pushed module 'I2', an HTTP/WebSocket flood generator, live through this loader. I2's HTTP-flood component POSTed a roughly 1-million-character payload every 500ms, producing about 2MB/second of upload traffic per active browser (roughly 2GB/second aggregate across 1,000 simultaneous tabs). I2's WebSocket-flood component fetched a target list from websocket.txt and opened up to 1,024 concurrent WebSocket connections per browser, sending valid Wisp proxy-protocol CONNECT/CLOSE frames every 100ms against localhost:1 on remote Wisp servers -- generating on the order of 10,240 connection cycles/second per browser. This is a control-plane DDoS rather than a purely volumetric one: it exhausts file descriptors and floods logs on the target Wisp infrastructure rather than simply saturating bandwidth. Confirmed live-fire targets were cdn.caan.edu, the CDN of a nursing school in Matteson, Illinois, and lunaron.top, a rival Wisp proxy endpoint -- meaning part of the campaign's DDoS traffic was aimed at competing student-proxy services. End of May 2026, JFrog and SafeDep began investigating after live-flood traffic was observed; the operators stripped the malicious DDoS modules from the loader on 2026-05-31 once reporting began, reverting to adware-only behavior. On 2026-07-08 a second wave under a new/related account republished the cleaned-up adware-only build, bringing the campaign total to 148 packages; by 2026-07-14, most packages had been removed from npm, though the charlie-kirk package (versions 2.0.0 and 3.0.1) remained live.
Attribution: no known APT group. Both JFrog and SafeDep independently assess the operator as young/juvenile based on: package names (charlie-kirk, ilovefemboys, miguelphonk, ishowfeet1-20), an auto-publish.sh shell script left inside published tarballs that parallel-published packages (3 concurrent processes) with dynamically generated names, npm/GitHub a
Weaknesses (CWE)
CWE-494, CWE-829, CWE-1104, CWE-400
Target sectors: education, students, content-delivery, open-source-supply-chain
Target regions: Global, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1584, T1587.001, T1583.006, T1585, T1195.002, T1189, T1204.001, T1059.007, T1176, T1505.003