UK ICO, USCourts.gov... Thousands of websites hijacked by hidden crypto-mining code after popular plugin pwned (2024)

Thousands of websites around the world – from the UK's NHS and ICO to the US government's court system – were today secretly mining crypto-coins on netizens' web browsers for miscreants unknown.

The affected sites all use a fairly popular plugin called Browsealoud, made by Brit biz Texthelp, which reads out webpages for blind or partially sighted people.

This technology was compromised in some way – either by hackers or rogue insiders altering Browsealoud's source code – to silently inject Coinhive's Monero miner into every webpage offering Browsealoud.

For several hours today, anyone who visited a site that embedded Browsealoud inadvertently ran this hidden mining code on their computer, generating money for the miscreants behind the caper.

A list of 4,200-plus affected websites can be found here: they include The City University of New York (cuny.edu), Uncle Sam's court information portal (uscourts.gov), Lund University (lu.se), the UK's Student Loans Company (slc.co.uk), privacy watchdog The Information Commissioner's Office (ico.org.uk) and the Financial Ombudsman Service (financial-ombudsman.org.uk), plus a shedload of other .gov.uk and .gov.au sites, UK NHS services, and other organizations across the globe.

Manchester.gov.uk, NHSinform.scot, agriculture.gov.ie, Croydon.gov.uk, ouh.nhs.uk, legislation.qld.gov.au, the list goes on.

The Monero miner was added to Browsealoud's code some time between 0300 and 1145 UTC: here's a clean copy of its JavaScript, and the hacked version. Coinhive's code is mostly detected and stopped by antivirus packages and ad-blocking tools. The miner perishes when you close the browser tab, so if you have visited one of the affected sites, your computer shouldn't be infected: the code only runs while the tab is open.

UK ICO, USCourts.gov... Thousands of websites hijacked by hidden crypto-mining code after popular plugin pwned (1)

Scrambled ... A portion of the obfuscated mining code injected via Browsealoud today

The injected mining code was obfuscated, but when converted from hexadecimal back to ASCII it spelled out the necessary magic to summon Coinhive's stealthy JavaScript miner to the page.

Defense mechanism

The malicious code was first spotted by UK-based infosec consultant Scott Helme, and confirmed by The Register. He recommended webmasters try a technique called SRI – Subresource Integrity – which catches and blocks attempts by hackers to inject malicious code into strangers' websites.

Just about every non-trivial website on the planet loads in resources provided by other companies and organizations – from fonts and menu interfaces to screen readers and translator tools. If any one of these outside resources is hacked or tampered with to perform malicious actions, such as mine crypto-coins, all the websites relying on that compromised resource will end up pulling the evil code onto their pages and into visitors' browsers.

UK ICO, USCourts.gov... Thousands of websites hijacked by hidden crypto-mining code after popular plugin pwned (2)

Now that's taking the p... Sewage plant 'hacked' to craft crypto-coins

READ MORE

SRI uses a fingerprinting approach to stop vandalized JavaScript from being imported into webpages. If an internet dirtbag changes a third-party provider's source code, the alteration is detected and blocked by the individual websites using this signature technique.

Until more websites use this protection mechanism, third-party resource providers – like Browsealoud – will be targeted by criminals to spread miners, or worse, on thousands of websites. A scumbag simply has to hack one provider to effectively infect countless other webpages.

"Third parties like this are absolutely a prime target and have been for some time," Helme told El Reg today. "There's a technology called SRI (Sub-Resource Integrity) designed to fix exactly this problem, and unfortunately it seems that none of the affected sites were using it."

A spokesperson for Texthelp told us as we were preparing to publish that it has removed its Browsealoud code from the web while it probes the security co*ckup, shutting down the illicit Monero-crafting operation.

"We are addressing this immediately," the biz said via Twitter. "Our Browsealoud service has been temporarily disabled whilst our engineering team investigates."

Luckily, the injected code was just trying to slyly mine Monero coins – one XMR is worth $238.65 or £172.56 right now – rather than anything more malevolent, such as popping up dodgy ads, stealing passwords, snooping on keystrokes, or tricking people into installing malware.

Texthelp's altered JavaScript was pulled offline by 1600 UTC today, we can confirm, meaning the affected websites are, for now, back to normal. The UK's ICO has also switched its website to a minimal "maintenance" mode as a precaution. ®

Updated to add

“In light of other recent cyber attacks all over the world, we have been preparing for such an incident for the last year and our data security action plan was actioned straight away,” said Texthelp's chief technology officer Martin McKay in a statement.

“Texthelp has in place continuous automated security tests for Browsealoud, and these detected the modified file and as a result the product was taken offline.”

The company added that "no customer data has been accessed or lost," and "customers will receive a further update when the security investigation has been completed."

UK ICO, USCourts.gov... Thousands of websites hijacked by hidden crypto-mining code after popular plugin pwned (2024)

FAQs

Is crypto mining in the UK legal? ›

In the UK, Bitcoin and other crypto mining is legal, with no limits. However, there are customs fees to pay when importing mining equipment. And there is income tax and National Insurance to be paid on any cryptocurrencies received from mining.

Is buying Bitcoin legal in the UK? ›

While the legal status of cryptocurrencies varies from one country to another, buying Bitcoin (BTC) and Ether (ETH) is entirely legal in the U.K., with a well-defined regulatory framework in place.

Why has the UK banned crypto? ›

The FCA continues to believe cETNs and crypto derivatives are ill-suited for retail consumers due to the harm they pose. As a result, the ban on the sale of cETNs (and crypto derivatives) to retail consumers remains in place. The FCA continues to remind people that cryptoassets are high risk and largely unregulated.

Is mining allowed in the UK? ›

Other metallic and industrial minerals

Other minerals are in private ownership and, although there is no national licensing system for exploration and extraction, planning permission must be obtained from a mineral planning authority for their extraction.

Is it legal to mine ethereum in UK? ›

Accordingly, the mining and staking of cryptoassets fall outside of the existing regulatory perimeter and are not expressly regulated activities in the UK (apart from HMRC considering any profits derived from mining activities to be taxable for individuals and businesses either as trading profits or under the ...

Does the UK have crypto regulations? ›

Since 8 October 2023, firms wishing to promote cryptoassets in the UK to retail consumers must, by law, be authorised or registered by the FCA, or have their marketing approved by an authorised firm.

Is Bitcoin mining taxable in the UK? ›

HMRC say that income from mining is treated as trading income if the activity is of the nature of a trade. Otherwise, the income is treated as miscellaneous income. For more information, see below under the Trading heading. In either case, the income is taxable.

Top Articles
How to Recover Microsoft Authenticator without Old Phone
Average US Household Gold Ownership and Legality Stats
Shoe Game Lit Svg
South Park Season 26 Kisscartoon
Crossed Eyes (Strabismus): Symptoms, Causes, and Diagnosis
Northern Whooping Crane Festival highlights conservation and collaboration in Fort Smith, N.W.T. | CBC News
Lost Ark Thar Rapport Unlock
Soap2Day Autoplay
My Vidant Chart
Love Compatibility Test / Calculator by Horoscope | MyAstrology
Ave Bradley, Global SVP of design and creative director at Kimpton Hotels & Restaurants | Hospitality Interiors
Vichatter Gifs
Goldsboro Daily News Obituaries
Caresha Please Discount Code
Walmart End Table Lamps
Grasons Estate Sales Tucson
Price Of Gas At Sam's
Chelactiv Max Cream
1-833-955-4522
Www Craigslist Milwaukee Wi
All Obituaries | Buie's Funeral Home | Raeford NC funeral home and cremation
Huntersville Town Billboards
Understanding Genetics
Baja Boats For Sale On Craigslist
Talk To Me Showtimes Near Marcus Valley Grand Cinema
Move Relearner Infinite Fusion
Dal Tadka Recipe - Punjabi Dhaba Style
Restaurants In Shelby Montana
Gopher Hockey Forum
Downloahub
Home Auctions - Real Estate Auctions
Melissa N. Comics
Wasmo Link Telegram
Salons Open Near Me Today
new haven free stuff - craigslist
Microsoftlicentiespecialist.nl - Microcenter - ICT voor het MKB
Baywatch 2017 123Movies
Sunrise Garden Beach Resort - Select Hurghada günstig buchen | billareisen.at
Miracle Shoes Ff6
Frommer's Philadelphia & the Amish Country (2007) (Frommer's Complete) - PDF Free Download
303-615-0055
Hireright Applicant Center Login
Lovely Nails Prices (2024) – Salon Rates
5A Division 1 Playoff Bracket
Senior Houses For Sale Near Me
Boyfriends Extra Chapter 6
Bonecrusher Upgrade Rs3
Understanding & Applying Carroll's Pyramid of Corporate Social Responsibility
Where and How to Watch Sound of Freedom | Angel Studios
Gameplay Clarkston
Famous Dave's BBQ Catering, BBQ Catering Packages, Handcrafted Catering, Famous Dave's | Famous Dave's BBQ Restaurant
Latest Posts
Article information

Author: Manual Maggio

Last Updated:

Views: 6223

Rating: 4.9 / 5 (49 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Manual Maggio

Birthday: 1998-01-20

Address: 359 Kelvin Stream, Lake Eldonview, MT 33517-1242

Phone: +577037762465

Job: Product Hospitality Supervisor

Hobby: Gardening, Web surfing, Video gaming, Amateur radio, Flag Football, Reading, Table tennis

Introduction: My name is Manual Maggio, I am a thankful, tender, adventurous, delightful, fantastic, proud, graceful person who loves writing and wants to share my knowledge and understanding with you.