Skip to main content

Tag: javascript injection

6 articles

Person sitting with laptop, hands on keyboard, contemplating a blurred browser screen.

Telegram Flaw Exposes User Messages via Hidden JavaScript in HTML Exports

A security flaw in Telegram Desktop's HTML export feature allowed hidden JavaScript to be embedded in exported chat pages, putting user messages at risk - and thankfully, it's now fixed!

Analyst 207
Person sitting at desk with computer displaying a blank webpage.

ClickFix Injects Malicious Scripts into Browsers to Siphon Cryptocurrency

A notorious fraud operation has taken a disturbing leap, evolving from tricking victims into running malicious commands on their computers to injecting harmful code directly into their browsers - all while masquerading as routine requests. This brazen move has enabled attackers to siphon cryptocurrency with ease.

Analyst 207
Brightly-lit office with rows of computer servers and a large screen displaying a blurred image.

Hackers Inject Malicious Script in Polymarket Supply-Chain Attack

Polymarket has pledged to fully reimburse customers who lost around $3 million in a shocking supply-chain attack that injected malicious JavaScript into the platform's frontend via a third-party vendor breach. The incident highlights the vulnerability of even major players to these types of attacks.

Analyst 207
Google Chrome browser window on laptop with YouTube open, surrounded by home office setting.

Popular Chrome Ad Blocker Exposes Script Injection Risk

A popular Chrome ad blocker with over 10 million installs, Adblock for YouTube, has been found to have a shocking vulnerability that could allow hackers to inject malicious JavaScript into any website, all with just a single server-side tweak. This means users could be exposed to serious security risks without even realizing anything has changed.

Analyst 207
WordPress plugin developer's workspace with code on screen, coffee, and notes on a minimalist wooden desk.

Malicious Code Infiltrates WordPress Plugins, Creates Rogue Admin Accounts

Over 1.2 million WordPress sites are at risk after attackers infiltrated a trusted vendor's network, injecting malicious code into popular plugins like OptinMonster, TrustPulse, and PushEngage. This sneaky hack creates rogue admin accounts, putting sites at risk of takeover - all without ordinary visitors even noticing.

Analyst 207
Retail checkout counter with a WooCommerce point-of-sale terminal in the foreground and blurred store shelves in the…

Funnel Builder Flaw Exploited for WooCommerce Checkout Skimming

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited, allowing attackers to inject malicious JavaScript into WooCommerce checkout pages and skim sensitive customer info. Over 40,000 online stores using the plugin may be at risk.

Analyst 207