SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Thousands of Websites Hijacked by Hidden Crypto-Mining Code After Popular Plugin Pwned
Date    Tuesday February 13, @12:51PM
Author    Fnord666
Topic   
from the plosives-galore dept.
https://soylentnews.org/article.pl?sid=18/02/13/0415201

MrPlow writes:

Submitted via IRC for Bytram

Thousands of websites around the world – from the UK's NHS and ICO to the US government's court system – were today secretly mining crypto-coins on netizens' web browsers for miscreants unknown.

The affected sites all use a fairly popular plugin called Browsealoud, made by Brit biz Texthelp, which reads out webpages for blind or partially sighted people.

This technology was compromised in some way – either by hackers or rogue insiders altering Browsealoud's source code – to silently inject Coinhive's Monero miner into every webpage offering Browsealoud.

For several hours today, anyone who visited a site that embedded Browsealoud inadvertently ran this hidden mining code on their computer, generating money for the miscreants behind the caper.

Source: https://www.theregister.co.uk/2018/02/11/browsealoud_compromised_coinhive/


Original Submission

Links

  1. "MrPlow" - https://soylentnews.org/~MrPlow/
  2. "Coinhive's Monero miner" - https://www.theregister.co.uk/2017/10/19/malwarebytes_blocking_coin_hive_browser_cryptocurrency_miner_after_user_revolt/
  3. "Browsealoud" - https://www.texthelp.com/en-gb/products/browsealoud/
  4. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=24803

© Copyright 2018 - SoylentNews, All Rights Reserved

printed from SoylentNews, Thousands of Websites Hijacked by Hidden Crypto-Mining Code After Popular Plugin Pwned on 2018-02-21 03:57:53