BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Stealth Monero Mining Scripts Infect 3,500+ Websites Worldwide

Over 3,500 Websites Compromised in Ongoing Monero Cryptojacking Campaign Using Stealthy Mining Scripts

  • Over 3,500 websites have hidden Monero mining scripts installed through a malicious injection chain.
  • Hackers are reusing old access points, mainly on unpatched and e-commerce servers, to deliver these scripts.
  • The mining Malware limits the use of system resources to avoid detection by standard security tools.
  • The campaign is ongoing and was first discovered by Cybersecurity company c/side.
  • The scripts convert visitors’ browsers into Monero mining engines without stealing passwords or funds.

Attackers have compromised more than 3,500 websites to secretly run Monero mining scripts. The malicious software hijacks visitors’ browsers to mine Monero, a privacy-focused cryptocurrency, without user consent.

- Advertisement -

Cybersecurity researchers at c/side discovered the attack, which is still active. The Hackers delivered the mining script through a chain of malicious injections, often targeting unpatched websites and e-commerce servers.

The mining malware is designed to operate quietly. It limits CPU (computer processing unit) usage and hides network traffic using WebSocket streams to reduce the chances of being noticed by security tools. According to c/side, “By throttling CPU usage and hiding traffic in WebSocket streams, it avoided the telltale signs of traditional crypto jacking,” as disclosed in their recent blog post.

An unnamed security researcher stated to Decrypt that the hackers are leveraging infrastructure from previous campaigns, including access gained during past Magecart attacks. Magecart is a tactic involving the injection of code into online checkout pages to steal payment information. The attackers reportedly placed the Monero miner by adding an extra script to already-compromised sites: “Planting the miner was trivial, they simply added one more script to load the obfuscated JS, repurposing existing access.”

Unlike past attacks that overloaded users’ CPUs, the current approach uses WebAssembly code, which allows efficient mining, paired with WebSockets for constant, low-key server communication. The new scripts are designed to remain undetected, capping resource use so browsers do not show abnormal behavior.

- Advertisement -

The primary goal appears to be long-term, Passive income for attackers. The malware does not currently steal passwords or drain crypto wallets, although it could potentially be adapted to do so. The main targets are web server and app owners, not end users.

Cryptojacking, the hidden mining of cryptocurrency on someone else’s device, became widely known in 2017 with the rise of Coinhive, a service that was shut down in 2019. Since then, reports on its frequency have been mixed, but this new low-profile campaign points to a shift in how attackers are operating. For more background or technical analysis, visit the official disclosure from c/side.

âś… Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

McLaren Racing Joins Hedera Governing Council

McLaren Racing has joined the Hedera Council, gaining a governance role and launching digital...

Comic raised $50K for Gaza via staged memecoin rug pulls.

Comedian William Banks orchestrated a fabricated prison break video that garnered over 10 million...

TON Blockchain Cuts Block Times, Boosts Speed 6-Fold

The Open Network (TON) released its Catchain 2.0 consensus upgrade on Thursday, slashing block...

Insider Sell-Offs: Top Apple Executives Sold $24M In Stock In April

Two senior Apple executives sold a combined $24.2 million worth of corporate stock in...

Anti-Trump Ethereum Developer Runs for Congress in Virginia

Ethereum developer Joe Schiarizzi is running for Congress as a Democrat in Virginia, positioning...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading