Skip to main content

Government websites fall prey to a plugin injected with a digital coin miner

Thousands of websites relying on the Browsealoud plugin developed by U.K.-based Texthelp recently fell prey to a hack that secretly ran a cryptocurrency mining script in the background of visiting PCs. Websites use this specific plugin for visually impaired visitors so they can hear content, but on Sunday, February 11, someone managed to alter the plugin’s code to run Coinhive’s controversial JavaScript-based Monero digital currency miner. 

Because it’s based on JavaScript, administrators can easily insert Coinhive’s miner into a webpage. It runs in the background while visitors browse the website, silently mining digital coins using their PC’s processor. The CPU use can be extremely apparent if you know what’s going on, otherwise, the average web surfer may simply shrug off the slow performance as typical Windows or web-based processes slowing down the machine. The mining stops once web surfers leave the offending page. 

Recommended Videos

The altered Browsealoud plugin began mining Monero Sunday morning on more than 4,200 websites spanning the globe, including governments, organizations, and schools. Among them was the State of Indiana, the U.S. court information portal, the City University of New York, the U.K.’s National Health Service, the U.K.’s Student Loans Company, and many more. 

Please enable Javascript to view this content

Most websites typically rely on plugins to pull content and tools from third-party developers. These can include translators, shopping baskets and ecommerce, menus, and so on. But the discovery of Coinhive’s miner in Browsealoud points to the possibility that if a hacker could gain access to one plugin for malicious purposes, thousands of websites could suffer. 

Plugin content typically resides on a remote server and sent to the target web page using a secure connection. The problem is that there is no real system to authenticate the actual content. Thus, someone with access to the content could easily inject malicious code, and the resulting websites using the plugin would serve up the malicious content despite registering the server as secure. 

One method to fix this problem is called Subresource Integrity. It comprises of two HTML elements with an “integrity” attribute that relies on a cryptographic hash. If the number provided to the website doesn’t match the number associated by the content, then the website can catch and block the malicious code. Unfortunately, this isn’t a widely used technique, but the recent issue with Browsealoud may convince more websites to utilize the Subresource Integrity method. 

Coinhive’s miner was reportedly only active in the Browsealoud plugin for a few hours before Texthelp pulled the plug. And although the outcome was apparently only to generate digital coin, the company still considers the hack as a criminal act. 

“Texthelp has in place continuous automated security tests for Browsealoud — these tests detected the modified file and as a result, the product was taken offline,” Texthelp Chief Technical Officer Martin McKay said in a statement. “This removed Browsealoud from all our customer sites immediately, addressing the security risk without our customers having to take any action.” 

Texthelp is currently working with the National Crime Agency and the National Cyber Security Agency to hunt down the hacker(s). 

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
China joins the global push for AI content regulation
AI chatbots.

Many international entities are pushing for better regulation of AI-generated content on the internet– and China’s government is the latest to reign in the use of the quickly developing technology.

According to Bloomberg, several government ministries have joined with the Chinese internet watchdog Cyberspace Administration of China (CAC) to announce a new mandate that will require internet users to identify any AI-generated content as such in a description or metadata encoding.

Read more
Nvidia RTX 50 series owners can unlock free GDDR7 memory speed boost
Screenshots of MSI Afterburner over a colorful background.

Popular graphics card monitoring and overclocking tool, MSI Afterburner, has received a beta update enabling owners of Nvidia’s RTX 50-series GPUs to boost their GDDR7 memory speeds by up to 10%. This enhancement allows data transfer rates to reach up to 36 gigatransfers per second (GT/s), surpassing Nvidia's standard specifications.

The RTX 50-series graphics cards are equipped with GDDR7 memory modules rated between 28GT/s and 32GT/s. However, Nvidia often sets default data transfer rates slightly lower, at 28GT/s for most models and 30GT/s for the RTX 5080, to ensure stability and longevity. The new update to MSI Afterburner unlocks the potential to exceed these factory settings, offering enthusiasts the opportunity to maximize their hardware's performance.

Read more
Open source image editor GIMP makes comeback after seven years
GIMP 3.0 splash screen

After seven years of work, the GNU Image Manipulation Program (GIMP) team has officially released GIMP 3.0, bringing a major update to the popular open-source image editor.

A cornerstone of the latest release is the transition to the GTK3 graphical user interface library, replacing the outdated GTK2. This upgrade is said to enhance the application's performance and introduces a more contemporary and responsive user interface. GIMP 3.0 also introduces non-destructive editing capabilities for many commonly used filters. This feature allows users to preview changes in real-time directly on the canvas.

Read more