Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Federal officials propose breakup of PJM Interconnection amid soaring power prices

June 6, 2026

New Defend Developers PAC targets key races with DeFi on the line

June 6, 2026

Shiba Inu’s multi‑year low tests investor conviction – Traders turn bearish

June 6, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Crypto-Mining Malware Found on 4000+ Sites
Crypto-Mining Malware Found on 4000+ Sites
Security and Privacy

Crypto-Mining Malware Found on 4000+ Sites

September 6, 2023No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Over 4000 websites including several belonging to UK and US government agencies were found over the weekend to be running hidden crypto-mining malware.

Security researcher Scott Helme first investigated the website of the Information Commissioner’s Office (ICO) after a tip-off that AV filters were raising red flags.

“At first the obvious thought is that the ICO were compromised so I immediately started digging into this after firing off a few emails to contact people who may be able to help me with disclosure. I quickly realised though that this script, whilst present on the ICO website, was not being hosted by the ICO, it was included by a third-party library they loaded” he explained.

“If you want to load a crypto miner on 1,000 websites you don’t attack 1,000 websites, you attack the one website that they all load content from. In this case it turned out that Texthelp, an assistive technology provider, had been compromised and one of their hosted script files changed.”

It turned out that attackers had compromised a JavaScript file which was part of the Texthelp Browsealout product, adding malicious code which effectively installed the CoinHive miner.

Some of the sites affected by CoinHive included United States Courts, the General Medical Council, the UK’s Student Loans Company, NHS Inform and many others.

Helme argued that mitigating the attack only requires a small code change to how the Browsealoud script is loaded.

“What I’ve done here is add the SRI Integrity Attribute and that allows the browser to determine if the file has been modified, which allows it to reject the file. You can easily generate the appropriate script tags using the SRI Hash Generator and rest assured the crypto miner could not have found its way into the page,” he explained.

See also  Cthulhu Stealer Malware Targets macOS With Deceptive Tactics

“To take this one step further and ensure absolute protection, you can use Content Security Policy and the require-sri-for directive to make sure that no script is allowed to load on the page without an SRI integrity attribute.”

The good news is the attack took place on Sunday morning and Texthelp has been quick to recognise the issue and take its service temporarily offline to fix it.

Crypto-mining is an increasingly popular way for cyber-criminals to make money; in fact, many are turning away from ransomware to focus on the new tactic, according to Cisco Talos.

IBM claimed to have seen a six-fold increase crypto-mining malware attacks between January and August 2017.

Source link

Cryptomining Malware Sites
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

June 3, 2026

Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

May 29, 2026

Certik Unveils ‘Anti-Virus for AI Agents’ as Skill Marketplaces Face Hidden Threats

May 29, 2026

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Bitcoin Price Nosedives Below Support As Bears Target $25K

June 6, 2023

Ripple CLO Finds ‘So Much Wrong’ in SEC’s Coinbase Brief

October 7, 2023

SEC Sues Consensys Over MetaMask Staking, Broker Allegations

June 28, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Federal officials propose breakup of PJM Interconnection amid soaring power prices

June 6, 2026

New Defend Developers PAC targets key races with DeFi on the line

June 6, 2026

Shiba Inu’s multi‑year low tests investor conviction – Traders turn bearish

June 6, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$60,297.00-3.94%
  • ethereumEthereum(ETH)$1,543.39-10.53%
  • tetherTether(USDT)$1.000.09%
  • binancecoinBNB(BNB)$568.16-4.88%
  • usd-coinUSDC(USDC)$1.000.01%
  • rippleXRP(XRP)$1.08-5.79%
  • solanaSolana(SOL)$61.96-7.97%
  • tronTRON(TRX)$0.320084-2.44%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.95%
  • HyperliquidHyperliquid(HYPE)$58.34-7.04%