newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: Over 269,000 websites infected with JSFiretruck JavaScript malware
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > Over 269,000 websites infected with JSFiretruck JavaScript malware
Technology

Over 269,000 websites infected with JSFiretruck JavaScript malware

June 13, 2025 4 Min Read
Share
Over 269,000 websites infected with JSFiretruck JavaScript malware
SHARE

Cybersecurity researchers are paying attention to “large campaigns” that undermine legitimate websites with malicious JavaScript injections.

According to Palo Alto Networks Unit 42, these malicious injections are obfuscated using JSFuck. This refers to an “exorable and educational programming style” in which code is written and executed using only a limited set of characters.

Cybersecurity companies have given the technique an alternative name for JSFiretruck for blasphemy to be involved.

“Several websites have been identified in injected malicious JavaScript that uses JSFiretruck obfuscation, which consists primarily of symbols (), +, $, {, and }. “Obfuscation of code hides its true purpose and prevents analysis.”

Further analysis determined that the injection code was designed to check the website referrer (“Document.Referrer”) which identifies the address of the web page on which the request occurred.

Referers are Google, Bing, Duckduckgo, Yahoo! , or if it’s a search engine like AOL, JavaScript code will redirect victims to malicious URLs that can provide malware, exploits, traffic monetization, and fraud.

Unit 42 said 269,552 web pages were discovered that were infected with JavaScript code using the JSFiretruck technique between March 26th and April 25th, 2025. The campaign surge was recorded on April 12, when over 50,000 infected web pages were recorded in one day.

“The size and stealth of the campaign pose a huge threat,” the researcher said. “The broad nature of these infections suggests coordinated efforts to compromise legitimate websites as an attack vector for further malicious activities.”

Say hellotds

Development is underway as Gen Digital has removed site visitors from fake Captcha pages, technical support scams, fake browser updates, unnecessary browser extensions, and sophisticated traffic delivery service (TDS), called HellotDS, designed to start a site using the site to start a site with fake Captcha pages, technical support scams, fake browser updates, unnecessary browser extensions, and Cryptocurrency Scams via rimmed JavaScript code.

See also  How to stop the AI ​​drawing of iPhone in a past era

The main purpose of TDS is to act as a gateway and determine the exact nature of content delivered to the victim after fingerprinting the device. If the user is not considered the appropriate target, the victim will be redirected to a benign web page.

“The campaign entry points are fraudulent or attacker-controlled streaming websites, file sharing services, and campaigns,” researchers Vojtěch Krejsa and Milan Sipinka said in a report released this month.

“Victims are evaluated based on geographical, IP address, and browser fingerprints. For example, connections via a VPN or headless browser will be detected and rejected.”

Some of these attack chains are known to leverage Clickfix strategies to trick users into running malicious code and provide fake Captcha pages that infect machines with malware known as Peaklight (aka Emmenhtal Loader), known to server information steelers like Lumma.

The heart of the HelloTDS infrastructure is the use of top-level domains of .top, .shop, and .com, which are used to host JavaScript code and trigger redirects following a multi-stage fingering process designed to collect network and browser information.

“The Hellotds infrastructure behind the fake Captcha campaign shows that attackers continue to improve the way in which they circumvent traditional protections, avoid detection, and selectively target victims,” ​​the researchers said.

“By leveraging sophisticated fingerprints, dynamic domain infrastructure, and deception tactics (such as mimicking legitimate websites and providing benign content to researchers), these campaigns achieve both stealth and scale.”

Share This Article
Facebook Twitter Copy Link
Previous Article Anthony Santander opens up about his repeated battle with injuries after his long-awaited return for the Toronto Blue Jays Anthony Santander opens up about his repeated battle with injuries after his long-awaited return for the Toronto Blue Jays
Next Article You need to know what features you need with 6 new ChatGPT projects You need to know what features you need with 6 new ChatGPT projects
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

Chrome 0 Day, Data Wiper, Misuse Tool, Zero Click iPhone Attack
Technology

Chrome 0 Day, Data Wiper, Misuse Tool, Zero Click iPhone Attack

28 Min Read
Can AI solve the Loneliness epidemic?
Technology

Can AI solve the Loneliness epidemic?

8 Min Read
AI agents run on secret accounts – learn how to protect them in this webinar
Technology

AI agents run on secret accounts – learn how to protect them in this webinar

3 Min Read
Why is DNS security the first defense against cyber attacks?
Technology

Why is DNS security the first defense against cyber attacks?

8 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?