Categories: CryptoNews

Two CBS Websites Contained Code to Mine Monero

It appears plenty of websites are experimenting with cryptocurrency mining scripts these days. Now that two sites operated by CBS’s Showtime video network have been identified as containing such scripts, it will be interesting to see how the public responds. Up until now, only niche sites had experimented with this concept, but Showtime is a different creature altogether. No one knows for sure how the code got onto these websites in the first place, though.

Showtime Website Mines Cryptocurrency

Over the past week and a half, there have been numerous stories involving websites which suddenly started using visitors’ computer resources to mine cryptocurrency. In nearly every case, the mining process involved Monero, the only anonymous cryptocurrency in the world today. Although one would need significant computing resources to mine even one XMR these days, running a script on a website can still be pretty lucrative overall.

It is a mystery as to why Showtime would embed such code on two of its websites, though. The JavaScript code was identified over the weekend, and no one knows for sure how it made its way onto the website to begin with. The code is the same as that found on Coinhive, and is quickly becoming one of the most-hated JavaScript code pieces in history right now.  What is even more peculiar is how CBS claims no one on their staff embedded the code into the website.

Indeed, CBS has no good reason to have done so whatsoever. While everyone who runs a website is always looking for new ways to increase overall revenue, hijacking computer resources is never the best option. Additionally, CBS has a reputation to uphold, and one that is certainly not worth damaging for a few XMR mined through a browser. This hints that someone else successfully embedded the code on Showtime.com and ShowtimeAnytime.com without the company’s knowledge, which could prove to be a major problem.

Related Post

Moreover, Showtime is a paid service, which makes it even more unlikely that the Coinhive code was embedded in-house. Given the popularity of this platform globally, however, it is not entirely surprising that some nefarious individuals may have targeted these video-on-demand portals to embed JavaScript code capable of mining cryptocurrency. If someone effectively hacked the backend of both platforms, CBS will need to perform some proper security checks, to say the least.

One question currently being explored is whether the code in question was inserted using HTML tags related to web analytics provider New Relic. There is no reason to think this provider would purposefully let companies integrate a cryptocurrency mining scipt on its pages, but it shows that the potential attack vectors go well beyond the affected websites themselves. So far, New Relic claims to have had nothing to do with the code itself. Regardless of who is responsible, this sets a very intriguing and dangerous precedent.

It is not unlikely we will see more of these incidents moving forward. Mining cryptocurrency using someone else’s browser is anything but harmless; that much is evident. While it may not be the best way to earn money, it is still an attack vector a lot of criminals will continue to explore for quite some time to come. The code doesn’t stand out on a website either, which means it can remain in place for some time until users report an issue to the site owner. 

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Justin Sun Pledges $SUN Buybacks With SunPerp Revenue

Justin Sun, CEO of TRON DAO, has just made one of his biggest announcements of…

2 days ago

$BNB Hits $1,000 ATH as Market Cap Reaches $145.7B

$BNB has broken through a historic milestone. The token surged past $1,000, setting a new…

3 days ago

Top 5 DeFi Tokens Less Than $1 Price Mark To Watch In September

Decentralized finance (DeFi) has continued to disrupt traditional financial systems, offering permissionless access to lending,…

3 days ago

Solana Data Insights: App Revenues Hit $193.5M in August, Up 126% YoY

Solana’s app economy posted another breakout month. Total application revenues surged to $193.5 million in…

4 days ago

Sharps Technology Aligns with Bonk for Treasury Staking and Solana Growth

Sharps Technology (NASDAQ: STSS) is making a major move in the Solana ecosystem. The company,…

4 days ago

Understand AR In the Context of LivLive’s Game Layer for Reality Ecosystem

LivLive is redefining augmented reality (AR) gaming by turning real-world actions into measurable value for…

5 days ago