BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Over 3,500 Websites Hit by Stealth JavaScript Crypto Miners

Stealth JavaScript Miner Infects 3,500+ Websites in Global Crypto Mining and Credit Card Skimming Campaign

  • Over 3,500 websites worldwide have been secretly compromised to run JavaScript cryptocurrency mining code.
  • The malicious mining scripts use obfuscated JavaScript and Web Workers to perform background mining without alerting users or security software.
  • Attackers utilize WebSockets to fetch and manage mining tasks dynamically, keeping resource usage low for stealth operations.
  • The domain used for the miner has also been linked to Magecart credit card skimming, suggesting attackers are diversifying their methods.
  • Recent incidents include other website attacks, like redirect Malware and supply chain threats through WordPress plugins and themes.

A new cyberattack campaign has secretly infected more than 3,500 websites around the world with JavaScript code designed to mine cryptocurrency in users’ web browsers. The attacks were identified by researchers at c/side, who found that the compromised sites run a stealth mining operation, draining device resources without the user’s knowledge.

- Advertisement -

Researchers found that the mining code is hidden in scrambled JavaScript, which checks a device’s computing power and then launches background mining workers. These scripts make use of WebSockets to connect to an external server, enabling the attacker to adjust mining load based on the victim’s hardware. This method allows the mining process to go undetected by both users and many security tools.

Security researcher Himanshu Anand said, “This was a stealth miner, designed to avoid detection by staying below the radar of both users and security tools.” The investigations also revealed that the same domain responsible for the JavaScript miner has previously been involved in attacks to steal credit card details through Magecart skimming.

Attackers are seen expanding their efforts beyond mining by combining techniques. These include using domains linked to both cryptocurrency mining and deployment of credit card-stealing scripts on shopping websites. According to c/side, “Attackers now prioritize stealth over brute-force resource theft, using obfuscation, WebSockets, and infrastructure reuse to stay hidden.”

Other web-based attacks were also noted recently. Some Hackers have abused the callback feature in a legitimate Google OAuth endpoint (accounts.google.com/o/oauth2/revoke) to load malicious JavaScript and set up unauthorized connections. There have been cases of direct malware injection into WordPress databases using Google Tag Manager scripts, redirecting visitors to spam domains.

- Advertisement -

Additional incidents include hackers compromising WordPress files and themes, leading to unwanted browser redirects or injecting search engine spam. Attackers have even distributed backdoored versions of the Gravity Forms plugin, allowing them to take control of affected sites, as detailed in a recent security statement from the plugin’s developers.

These findings come alongside ongoing e-commerce skimming campaigns and highlight an evolving landscape of stealthy, profit-driven cyberattacks targeting both cryptocurrency and payment information.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Drake’s New Song Demands Pardon for SBF

Drake called for the release of imprisoned FTX founder Sam Bankman-Fried in a lyric...

NIO’s Onvo L80 SUV Launches, Deliveries Start Saturday

Nio's mass-market subsidiary, Onvo, officially launched the L80 family SUV on Friday, with deliveries...

Liberland Honors Ethereum Founder Buterin With Star-Shaped Medal

Vitalik Buterin received the "First Class Order of Merit of the Star of Liberland"...

Firm seeks $344M in frozen Tether tied to Iran

Gerstein Harrow LLP is seeking a court order to compel Tether to release over...

Turla’s Kazuar Malware Evolves Into Stealthy P2P Botnet

The Russian state-sponsored group Turla (aka Secret Blizzard) has evolved its Kazuar malware into...

Must Read

7 Best Crypto To Invest In This Year

Investing in cryptocurrencies has become a popular way for people to diversify their investment portfolio and make potential profits.However, with so many cryptocurrencies available...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading