YesNoOk
avatar

SafeBrowse extension & Showtime site infected with cryptocurrency mining scripts (Read 3580 times)

Started by Ricepigeon, September 26, 2017, 03:10:53 pm
Share this topic:
SafeBrowse extension & Showtime site infected with cryptocurrency mining scripts
#1  September 26, 2017, 03:10:53 pm
  • *****
  • Thanks and God bless
    • USA
    • ricepigeon.neocities.org
Source: https://fossbytes.com/safebrowse-chrome-extension-mines-cryptocurrency-using-your-cpu-power/

Quote
t’s being reported by gHacks that a popular Chrome extension named SafeBrowse has been found running a crytpo-mining module in the background. The mining activity keeps running in the background when the browser is running and the extension is enabled. If you’ve installed the latest updated version of this extension, you might be seeing an increased CPU usage when Chrome web browser is running. The extension makes connections to coin-hive.com.

In the latest development, SafeBrowse has been removed from Chrome Web Store. Prior to that, it had about 150,000 users. While this Chrome extension was mining Monero crypto coins without user notifications, it was installed via a legitimate path. It’s possible that in future, crypto mining extensions could also be installed using a malware attack.
Last Edit: September 26, 2017, 07:04:28 pm by Ricepigeon
Re: SafeBrowse extension for Chrome found to contain Cryptocurrency mining code
#2  September 26, 2017, 04:40:13 pm
  • avatar
  • ******
im sure it been done hundreds of time, and probably there are extension or programs out there that still does and not yet been caught.
Re: SafeBrowse extension for Chrome found to contain Cryptocurrency mining code
#3  September 26, 2017, 07:03:19 pm
  • *****
  • Thanks and God bless
    • USA
    • ricepigeon.neocities.org
In related news;

https://www.theregister.co.uk/2017/09/25/showtime_hit_with_coinmining_script/

Quote
The websites of US telly giant CBS's Showtime contained JavaScript that secretly commandeered viewers' web browsers over the weekend to mine cryptocurrency. The flagship Showtime.com and its instant-access ShowtimeAnytime.com sibling silently pulled in code that caused browsers to blow spare processor time calculating new Monero coins – a privacy-focused alternative to the ever-popular Bitcoin. The hidden software typically consumed as much as 60 per cent of CPU capacity on computers visiting the sites. The scripts were written by Code Hive, a legit outfit that provides JavaScript to website owners: webmasters add the code to their pages so that they can earn slivers of cash from each visitor as an alternative to serving adverts to generate revenue. Over time, money mined by the Code-Hive-hosted scripts adds up and is transferred from Coin Hive to the site's administrators.

The JavaScript, which appeared on the sites at the start of the weekend and vanished by Monday, sits between HTML comment tags that appear to be an insert from web analytics biz New Relic. Again, it is unlikely that an analytics company would deliberately stash coin-mining scripts onto its customers' pages, so the code must have come from another source – or was injected by miscreants who had compromised Showtime's systems.
Re: SafeBrowse extension & Showtime site infected with cryptocurrency mining scripts
#4  September 27, 2017, 03:56:39 am
  • *****
  • Hug Pikachus!
    • USA
How rude, using other people's computers to make money without permission...

Although how could I tell, as an average user, if my extensions are compromised with such scripts? I meant, if these miners are clever enough, they will make the CPU usage look like background noise...
Hug the Pikachus!

Hug A Pikachu Today!
Re: SafeBrowse extension & Showtime site infected with cryptocurrency mining scripts
#5  September 27, 2017, 05:11:47 am
  • ******
  • 90's Kawaii
  • :thinking:
    • Guatemala
I'd be more concerned about conventional malware being used to hijack my resources. There's only so much browser extensions can do, so the game of mouse and cat between stealth mining and anti-mining scripts can't go on forever.

Shame nobody from Pirate Bay to fucking CBS is being transparent about mining. This model is a really good alternative to ads, considering it doesn't require a third party and all the reeeeee'ing and virtue signaling in the world won't cause a site to get demotized.