4,200+ websites, including USCourts.gov, UK's NHS services, other government sites were infected with cryptocurrency mining malware via hacked plugin
Biz scrambles to shut down crafty coin crafting operation — Thousands of websites around the world - from the UK's NHS and ICO …
Context & Ripple Effects
This lands mid-wave: Symantec had already logged an 8,500% quarterly surge in cryptojacking through late 2017, driven by point-and-click mining kits built around Coinhive's browser-based Monero miner. Earlier compromises like the surreptitious miners found on Politifact showed individual sites being hit one at a time.
What changed here is scale through a single dependency: one hacked plugin pushed mining code onto 4,200+ sites at once, including USCourts.gov and NHS services — turning a per-site nuisance into a mass infection of high-trust government domains.
First-order effects
- Every visitor to the infected pages — including users of USCourts.gov and NHS services — had their device's CPU silently diverted to mining Monero until the operator behind the plugin scrambled to shut the operation down.
- The affected government and public-sector operators face immediate cleanup and questions about how third-party code reached their production sites.
Second-order effects
- Site operators are pushed toward stricter control of embedded scripts — allowlists, subresource integrity, and miner-blocking extensions — because any single trusted plugin becomes a distribution channel for thousands of domains.
- Browser vendors and ad-blockers gain pressure to treat drive-by miners as malware by default, squeezing the economics of legitimate-looking mining services like Coinhive.
Third-order effects
- The pattern points to supply-chain attacks on shared web infrastructure as the dominant cryptojacking vector — a path later echoed when 415K+ MikroTik routers were infected with miners and EU supercomputers were hit via stolen SSH credentials, each showing one compromise scaling across many machines.
- If shared plugins and appliances keep serving as infection multipliers, procurement rules for government sites will likely harden around provenance and auditing of third-party code.
The trend: Cryptojacking is evolving from opportunistic single-site injections into supply-chain attacks that weaponize shared infrastructure — plugins, routers, credentials — to harvest compute at scale.