Skip to main content

Government websites fall prey to a plugin injected with a digital coin miner

government monero
Image used with permission by copyright holder

Thousands of websites relying on the Browsealoud plugin developed by U.K.-based Texthelp recently fell prey to a hack that secretly ran a cryptocurrency mining script in the background of visiting PCs. Websites use this specific plugin for visually impaired visitors so they can hear content, but on Sunday, February 11, someone managed to alter the plugin’s code to run Coinhive’s controversial JavaScript-based Monero digital currency miner. 

Because it’s based on JavaScript, administrators can easily insert Coinhive’s miner into a webpage. It runs in the background while visitors browse the website, silently mining digital coins using their PC’s processor. The CPU use can be extremely apparent if you know what’s going on, otherwise, the average web surfer may simply shrug off the slow performance as typical Windows or web-based processes slowing down the machine. The mining stops once web surfers leave the offending page. 

The altered Browsealoud plugin began mining Monero Sunday morning on more than 4,200 websites spanning the globe, including governments, organizations, and schools. Among them was the State of Indiana, the U.S. court information portal, the City University of New York, the U.K.’s National Health Service, the U.K.’s Student Loans Company, and many more. 

Most websites typically rely on plugins to pull content and tools from third-party developers. These can include translators, shopping baskets and ecommerce, menus, and so on. But the discovery of Coinhive’s miner in Browsealoud points to the possibility that if a hacker could gain access to one plugin for malicious purposes, thousands of websites could suffer. 

Plugin content typically resides on a remote server and sent to the target web page using a secure connection. The problem is that there is no real system to authenticate the actual content. Thus, someone with access to the content could easily inject malicious code, and the resulting websites using the plugin would serve up the malicious content despite registering the server as secure. 

One method to fix this problem is called Subresource Integrity. It comprises of two HTML elements with an “integrity” attribute that relies on a cryptographic hash. If the number provided to the website doesn’t match the number associated by the content, then the website can catch and block the malicious code. Unfortunately, this isn’t a widely used technique, but the recent issue with Browsealoud may convince more websites to utilize the Subresource Integrity method. 

Coinhive’s miner was reportedly only active in the Browsealoud plugin for a few hours before Texthelp pulled the plug. And although the outcome was apparently only to generate digital coin, the company still considers the hack as a criminal act. 

“Texthelp has in place continuous automated security tests for Browsealoud — these tests detected the modified file and as a result, the product was taken offline,” Texthelp Chief Technical Officer Martin McKay said in a statement. “This removed Browsealoud from all our customer sites immediately, addressing the security risk without our customers having to take any action.” 

Texthelp is currently working with the National Crime Agency and the National Cyber Security Agency to hunt down the hacker(s). 

Editors' Recommendations

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Blue Screen of Death: What it means and what to do if you get one
The Blue Screen of Death seen on a laptop.

The BSOD, or Blue Screen of Death, is an iconic error screen that anyone who's ever used a Windows PC has liekly come across at one time or another. It's no fun, and it can mean there's a problem with your PC that needs fixing. But in most cases, it's just one of those things that crops up, and simply keeping your PC updated will be enough to prevent it from coming up again.

Here's everything you need to know about BSODs and what to do if youget one.
What is a BSOD?
The stop error screen, or as it's colloquially known for its blue coloring, the BSOD, is an error screen that appears when something has gone critically wrong with your PC. It doesn't mean it's fundamentally broken, but it means something has gone so wrong with it that it can no longer function and needs to reboot to get working again.

Read more
Best Samsung Galaxy deals: S24, Buds, Watches and more
The Galaxy Z Fold 4's Cover Screen.

Samsung’s Galaxy lineup is made up of several different types of devices, and if you’re in the market for some savings, you’ll often find Samsung Galaxy tech among the best headphone deals, the best smartwatch deals, the best tablet deals, and the best phone deals. With so many different devices among the Galaxy lineup, and with so many Samsung Galaxy deals out there for the picking, we rounded up what we feel are the best Samsung Galaxy deals to shop right now. Reading onward you’ll find discounts on some of the best tablets, best smartwatches, and best wireless earbuds the Samsung Galaxy lineup has to offer, as well as some impressive discounts on Galaxy phones.
Samsung Galaxy Buds 2 -- $97, was $150

If you're looking for headphone deals but you want an alternative to Apple's AirPods, you should consider the Samsung Galaxy Buds 2. The wireless earbuds have great battery life that's made even better with an included charging case. While some of the other Galaxy Buds out there include the Galaxy Buds Live, Galaxy Buds Pro, and Galaxy Buds+, but with the Galaxy Buds 2's active noise-cancelation you can block out unwanted sounds and keep your focus on whatever you’re working on, watching, or listening to. You can also control the headphones with touch controls on each earbud, and they connect easily to any Bluetooth device.

Read more
Best Microsoft Office deals: Get Word, PowerPoint, and Excel for free
Students using Microsoft Office software on their laptops outside.

While the fight of Microsoft vs Google when it comes to office apps might be never-ending, if you're the sort of person who prefers dealing with Microsoft, you'll be happy to know that there are quite a few good deals you can take advantage of. As you may know, most of Microsoft's apps have gone under one rather expensive subscription service, Microsoft 365, but you can still get older parts of the suite for relatively good prices. In fact, you can even get a free trial of Microsoft Word to test it out, although you'd still need to pay to get the full suite of tools.
Best Microsoft Office deals
Microsoft Office is a pay once, receive once service. You don't have to pay recurring monthly fees to use it, but the software also never updates. For what it's worth, the Microsoft Office packages are labelled "2021", so they're all fairly recent but also ripe for a good deal. With the exception of AI integrations, not much has really changed in the past couple of years when it comes to your basic document creation and these programs should continue to be effective for years to come. Depending on what package you get, you'll get access to different apps, based on the needs of the target audience. For example, Microsoft Office Home & Student 2021 keeps it lean and cool and with Microsoft Word, Microsoft Excel, and Microsoft PowerPoint being the only apps included.

Here are our favorite deals for the classic Microsoft Office experience:

Read more