BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

JSFireTruck JavaScript Attack Infects 269,000+ Web Pages in 2025

JSFireTruck Campaign Infects 270,000+ Websites with Obfuscated JavaScript, Redirects Search Engine Traffic to Malware and Scams

  • Researchers identified a widespread campaign using obfuscated JavaScript to infect legitimate websites.
  • The campaign, named “JSFireTruck,” uses an obscure coding technique to hide the real purpose of the code.
  • Compromised websites redirect users coming from search engines to malicious links that may deliver Malware or scams.
  • Nearly 270,000 web pages were reported infected between March and April 2025, with a major spike in mid-April.
  • A separate service, HelloTDS, is used to conditionally redirect users to scams like fake browser updates and cryptocurrency frauds.

Cybersecurity experts reported a large-scale attack infecting legitimate websites with hidden JavaScript code. The campaign actively redirects users to dangerous pages if they arrive from popular search engines, increasing the risk of malware or scam exposure.

- Advertisement -

Research from Palo Alto Networks Unit 42 found 269,552 web pages infected with obfuscated JavaScript between March 26 and April 25, 2025. A single day in April saw over 50,000 compromised pages. The unsafe code relies on a method known as “JSFuck,” an approach that writes programs using only a few characters to make detection and analysis harder.

According to security researchers Hardik Shah, Brad Duncan, and Pranay Kumar Chhaparwal, the team observed that multiple sites contained malicious JavaScript using a unique technique called JSFireTruck. The injected code checks if visitors arrive from search engines like Google, Bing, DuckDuckGo, Yahoo!, or AOL. If they do, it redirects them to malicious websites that can deliver malware, exploit kits, or fraudulent ads. “The code’s obfuscation hides its true purpose, hindering analysis,” the authors explained. The widespread infections suggest a coordinated effort to use real websites as tools for further attacks.

The report also highlights the emergence of “HelloTDS,” a Traffic Distribution Service that picks which scam to show a victim based on their device details. Gen Digital described how HelloTDS delivers fake CAPTCHA puzzles, tech support scams, bogus browser upgrades, and cryptocurrency fraud using JavaScript code hosted on remote sites. Victims are screened using information such as their location, IP address, and browser behavior. If the user does not match specific attack conditions, the code sends them to safe content instead.

Researchers Vojtěch Krejsa and Milan Špinka noted that attackers often disguise their activity on streaming sites, file-sharing platforms, or through malicious ads. Some schemes use trick questions to get users to run harmful software, like PEAKLIGHT, which is known for stealing sensitive information.

- Advertisement -

The infrastructure supporting HelloTDS mainly uses generic top-level domains such as .top, .shop, and .com to host harmful code. The campaigns incorporate advanced tactics such as browser fingerprinting and switching domains to avoid detection, making it harder for security tools to block attacks.

For more, see the original analysis by Palo Alto Networks Unit 42 here and Gen Digital‘s details on HelloTDS here. Information on the JSFuck technique can be found at this resource.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

RateON Review: A Convenient Crypto Exchange Platform With Broad Coverage and Extra Rewards

TABLE OF CONTENTSWhat Is RateON?Supported Coins and NetworksHow the Exchange Process WorksRates and Overall...

BlackRock-Backed Broadridge Scales $8T Tokenization

Broadridge is scaling its blockchain infrastructure, which already handles $8 trillion in tokenized assets...

China Aims to Boost Small Biz Loans With Blockchain

Chinese banking and tax authorities have directed financial institutions to adopt blockchain and privacy...

German Police ID REvil Ransomware Boss Behind $40M Hits

German authorities have identified Daniil Shchukin, 31, as the Russian threat actor “UNKN,” a...

Shiba Inu’s “Middle Age” Crisis: Collapse Risk Grows

Once dubbed "The Dogecoin Killer", Shiba Inu's price action has stabilized, leaving its wild,...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading