HomeSecurityTax filing software eFile.com distributes JavaScript malware

eFile.com tax filing software distributes JavaScript malware

A disturbing revelation has emerged – eFile.com, an IRS-approved e-filing platform used by countless taxpayers to file their tax returns, is distributing JavaScript malware!

eFile.com tax filing software distributes JavaScript malware

After extensive research, security analysts concluded that a malicious JavaScript file had been lingering on the eFile.com website for weeks. To corroborate their findings, BleepingComputer confirmed the presence of this dangerous code at the time of the investigation.

Please note that this security incident concerns eFile.com and is not related to other similar domains.

See also: Hackers appear to have breached Equifax's email system

Just in time for tax season

Many users and researchers discovered that eFile.com distributes malware, specifically a JavaScript file named 'popper.js'.

eFile.com tax filing software distributes JavaScript malware

At this critical juncture, as taxpayers complete their tax returns to the IRS before the April 18th deadline.

The highlighted code above is base64 encoded with its decoded version shown below. The code attempts to load JavaScript returned from infoamanewonliag[.]online:

eFile.com tax filing software distributes JavaScript malware

To ensure that eFile.com visitors receive the most up-to-date version of their malicious code, the threat actors add a Math.random() call to the end of this malware – ensuring that it is not cached and is always downloaded fresh with any modifications they have made. Fortunately, so far, this endpoint appears to be inactive.

As verified by BleepingComputer, the malicious JavaScript file 'popper.js' was loading on almost every page of eFile.com as of April 1, a worrying example of the security risk to users visiting this site.

eFile.com tax filing software distributes JavaScript malware

As of today, the file no longer appears to serve malicious code.

See also: Cybersecurity: Remote workers still pose a number of risks

The website was “hijacked” more than 2 weeks ago

On March 17, a suspicious Reddit thread went viral and revealed that many eFile.com users were convinced that the site had been “hijacked.”.

When the site was initially examined, an SSL error message appeared that could be a sign of a breach - some believed it might be fabricated.

eFile.com tax filing software distributes JavaScript malware

Surprisingly, this turned out to be correct: researchers identified a side file referred to as “update.js,” which was associated with the attack and hosted by an Amazon AWS endpoint.

After BleepingComputer obtained the 'update.js' file, it was discovered that a fake SSL error message was encoded in base64 HTML code (see below).

eFile.com javascript malware

An HTML snippet from the decoded string that generates the fake SSL error is shown below:

eFile.com

The malicious JavaScript file 'update.js' further attempts to trick users into downloading the next-stage payload, depending on whether they are using Chrome [update.exe – VirusTotal] or Firefox [installer.exe – VirusTotal]. Antivirus products have already started flagging these executables as trojans.

BleepingComputer has independently confirmed that these binaries create a connection to an IP address in Tokyo, 47.245.6.91, which appears to be hosted by Alibaba. The same IP also hosts the illegal domain, infoamaneewonliag[.]online, associated with this incident.

MalwareHunterTeam, a security research group, further examined the binaries and discovered that they were built into PHP botnets for Windows. The team joked about this discovery before pointing out eFile.com's failure to leave this malicious code on website for several weeks without taking any action.

The full consequences of this attack, including whether or not eFile.com visitors and customers were successfully infected, are still uncertain at this time.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS