Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Government websites fall prey to a plugin injected with a digital coin miner

Add as a preferred source on Google

Thousands of websites relying on the Browsealoud plugin developed by U.K.-based Texthelp recently fell prey to a hack that secretly ran a cryptocurrency mining script in the background of visiting PCs. Websites use this specific plugin for visually impaired visitors so they can hear content, but on Sunday, February 11, someone managed to alter the plugin’s code to run Coinhive’s controversial JavaScript-based Monero digital currency miner. 

Because it’s based on JavaScript, administrators can easily insert Coinhive’s miner into a webpage. It runs in the background while visitors browse the website, silently mining digital coins using their PC’s processor. The CPU use can be extremely apparent if you know what’s going on, otherwise, the average web surfer may simply shrug off the slow performance as typical Windows or web-based processes slowing down the machine. The mining stops once web surfers leave the offending page. 

Recommended Videos

The altered Browsealoud plugin began mining Monero Sunday morning on more than 4,200 websites spanning the globe, including governments, organizations, and schools. Among them was the State of Indiana, the U.S. court information portal, the City University of New York, the U.K.’s National Health Service, the U.K.’s Student Loans Company, and many more. 

Most websites typically rely on plugins to pull content and tools from third-party developers. These can include translators, shopping baskets and ecommerce, menus, and so on. But the discovery of Coinhive’s miner in Browsealoud points to the possibility that if a hacker could gain access to one plugin for malicious purposes, thousands of websites could suffer. 

Plugin content typically resides on a remote server and sent to the target web page using a secure connection. The problem is that there is no real system to authenticate the actual content. Thus, someone with access to the content could easily inject malicious code, and the resulting websites using the plugin would serve up the malicious content despite registering the server as secure. 

One method to fix this problem is called Subresource Integrity. It comprises of two HTML elements with an “integrity” attribute that relies on a cryptographic hash. If the number provided to the website doesn’t match the number associated by the content, then the website can catch and block the malicious code. Unfortunately, this isn’t a widely used technique, but the recent issue with Browsealoud may convince more websites to utilize the Subresource Integrity method. 

Coinhive’s miner was reportedly only active in the Browsealoud plugin for a few hours before Texthelp pulled the plug. And although the outcome was apparently only to generate digital coin, the company still considers the hack as a criminal act. 

“Texthelp has in place continuous automated security tests for Browsealoud — these tests detected the modified file and as a result, the product was taken offline,” Texthelp Chief Technical Officer Martin McKay said in a statement. “This removed Browsealoud from all our customer sites immediately, addressing the security risk without our customers having to take any action.” 

Texthelp is currently working with the National Crime Agency and the National Cyber Security Agency to hunt down the hacker(s). 

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Qualcomm is set to ratchet up chip prices in September, and your next gadget upgrade could bear the brunt
The price hike could touch every Snapdragon-powered device category.
The new Qualcomm Snadragon 8 Elite Gen 5

I want you to sit with this for a second. Qualcomm, the company whose Snapdragon chips sit inside your Android phone and tablet, your Windows laptop, your Meta smart glasses, your Galaxy Watch, and your wireless earbuds, reportedly sent a letter to every major customer telling them prices are going up by double digits. 

The price hike will be in effect from September 1, 2026, a recent Bloomberg report claims. Essentially, all the companies placing their chip orders after that will pay a higher price. 

Read more
Stop fighting with your roomie over outlets and get one of these multi-port chargers before you head back to school
One plug, zero drama, all your devices charged by morning.
Satechi ChargeView

Your room has one wall outlet, and you have multiple devices that need power by morning. Phone, laptop, tablet, earbuds, they're all vying for the same socket, and the bricks you own are single-port relics that hog it for just one gadget. You could throw a power strip at the problem, but then you're staring at a tangle of multiple bricks and cables that's enough to give you the sweats. A good multi-port charger cuts all that mess, and could be the only thing standing between you and a dead phone or laptop before your morning classes.

Back-to-school season is a smart time to buy one. You're already thinking about what'll go on your desk or in your bag, so it's the natural point to replace a pile of single-port bricks with one charger that does it all. I dug through the current crop of multi-port chargers so you don't have to, and here are five worth your money.

Read more
OpenAI’s rogue AI hack was just the beginning, Hugging Face warns
OpenAI’s rogue AI has come back to bite it
OpenAI logo on Microsoft surface

Hugging Face already knows what it is like to be attacked by an autonomous AI agent. If one of its co-founders is right, plenty of other companies are going to find out soon. Thomas Wolf, co-founder and chief science officer of Hugging Face, has called the recent cyberattack carried out by OpenAI models a “wake-up call” for the technology industry.

Speaking to the BBC, Wolf warned that AI-driven intrusions could become one of the most common forms of cyberattack and said many companies have yet to realize how dramatically the threat has changed. This arrives after OpenAI disclosed that its models escaped a restricted cybersecurity evaluation environment and compromised Hugging Face while trying to obtain answers for the ExploitGym benchmark. So Wolf’s comments now give us a better idea of what the attack looked like from the other side.

Read more