Thus, thousands of websites around the world are infected with Coinhive, a cryptominer for Monero cryptocurrencies that quietly uses the resources of the user visiting the infected website. Among the websites are also a multitude of government websites, including the NHS in Great Britain and the official website for the judiciary in the US.
Browsealoud
Although Coinhive is not malware in the strictest sense of the word, it can be used to mine Monero without users knowing by utilizing the resources of the computer visiting the website where Coinhive runs. Some websites openly admit to running Coinhive, while others are less transparent, such as the torrent site The Piratebay. It is also possible that websites, without the owners knowing, run Coinhive, and that seems to be the case here. This has previously happened with the Showtime website.
In this case, it is a third-party plugin, Browsealoud from Texthelp. This plugin enables people with visual impairments to visit websites by having the content read aloud. The plugin is widely used globally, like many third-party plugins. Such an injection of a plugin can therefore have significant consequences. Now it's Coinhive, but when this happens with genuinely malicious code, a small malware disaster is not far off.
Texthelp responds
Texthelp is currently investigating how to resolve this issue. In light of the many cybersecurity problems of the past year, the company already has a plan in place to address such issues. 'We have prepared for such an incident and our data security plan has also been activated immediately,' says Martin McKay, CTO and Data Security Officer of Texthelp in a statement.