BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Over 3,500 Websites Hit by Stealth JavaScript Crypto Miners

Stealth JavaScript Miner Infects 3,500+ Websites in Global Crypto Mining and Credit Card Skimming Campaign

  • Over 3,500 websites worldwide have been secretly compromised to run JavaScript cryptocurrency mining code.
  • The malicious mining scripts use obfuscated JavaScript and Web Workers to perform background mining without alerting users or security software.
  • Attackers utilize WebSockets to fetch and manage mining tasks dynamically, keeping resource usage low for stealth operations.
  • The domain used for the miner has also been linked to Magecart credit card skimming, suggesting attackers are diversifying their methods.
  • Recent incidents include other website attacks, like redirect Malware and supply chain threats through WordPress plugins and themes.

A new cyberattack campaign has secretly infected more than 3,500 websites around the world with JavaScript code designed to mine cryptocurrency in users’ web browsers. The attacks were identified by researchers at c/side, who found that the compromised sites run a stealth mining operation, draining device resources without the user’s knowledge.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

Researchers found that the mining code is hidden in scrambled JavaScript, which checks a device’s computing power and then launches background mining workers. These scripts make use of WebSockets to connect to an external server, enabling the attacker to adjust mining load based on the victim’s hardware. This method allows the mining process to go undetected by both users and many security tools.

Security researcher Himanshu Anand said, “This was a stealth miner, designed to avoid detection by staying below the radar of both users and security tools.” The investigations also revealed that the same domain responsible for the JavaScript miner has previously been involved in attacks to steal credit card details through Magecart skimming.

Attackers are seen expanding their efforts beyond mining by combining techniques. These include using domains linked to both cryptocurrency mining and deployment of credit card-stealing scripts on shopping websites. According to c/side, “Attackers now prioritize stealth over brute-force resource theft, using obfuscation, WebSockets, and infrastructure reuse to stay hidden.”

Other web-based attacks were also noted recently. Some Hackers have abused the callback feature in a legitimate Google OAuth endpoint (accounts.google.com/o/oauth2/revoke) to load malicious JavaScript and set up unauthorized connections. There have been cases of direct malware injection into WordPress databases using Google Tag Manager scripts, redirecting visitors to spam domains.

- Advertisement -

Additional incidents include hackers compromising WordPress files and themes, leading to unwanted browser redirects or injecting search engine spam. Attackers have even distributed backdoored versions of the Gravity Forms plugin, allowing them to take control of affected sites, as detailed in a recent security statement from the plugin’s developers.

These findings come alongside ongoing e-commerce skimming campaigns and highlight an evolving landscape of stealthy, profit-driven cyberattacks targeting both cryptocurrency and payment information.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ethereum Aims for Quantum Resistance by 2029

The Ethereum Foundation has launched a "Post-Quantum Ethereum" resource hub to address future quantum...

NASA Shifts Artemis to Build $20B Permanent Moon Base

NASA has shifted its Artemis program strategy, now prioritizing the construction of a permanent...

War Sparks Cash Rush, Gold & Bonds Dumped

Bitcoin is under pressure as investors flee to cash, with Bitcoin retesting $67,500 support...

Circle Shares Plummet 20%; Tether Audit, Yield Bill Weigh

Circle's stock (CRCL) plummeted 20% on Tuesday, erasing recent gains.Rival Tether announced a major...

Robinhood announces $1.5B buyback plan over three years

Robinhood announced a new share repurchase program for up to $1.5 billion.The firm's shares...

Must Read

Tutorial: How to Buy a Domain Name Permanently? (Super Easy)

Are you ready to establish a permanent online presence and you want to buy a domain forever?In this tutorial, we'll show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading