HomeSecurity150,000 websites have been compromised by malicious JavaScript

150,000 websites have been compromised by malicious JavaScript

An ongoing campaign that infiltrates legitimate websites with malicious JavaScript to promote Chinese gaming platforms has affected approximately 150,000 websites.

See also: 'DollyWay' malware campaign compromised 20,000 WordPress sites

malicious JavaScript

According to statistics from PublicWWW, there are currently over 135,800 websites that contain JavaScript payload.

According to the website security firm's recording last month, the campaign involves infecting websites with malicious JavaScript, which is designed to take over a user's browser window and redirect visitors to pages promoting gambling platforms.

The redirects have been identified as occurring via malicious JavaScript hosted on five different domains (e.g., “zuizhongyj[.]com“), which in turn provide the main payload responsible for executing the redirects.

c /side also reported that it observed another variation of the campaign that involves inserting scripts and iframe into HTML, pretending to be legitimate betting websites such as Bet365, using official logos and branding.

See also: Malicious JavaScript: What it is and how to protect yourself

The ultimate goal is to present a full-screen overlay via CSS, which will display the fraudulent gambling page when someone visits one of the infected websites, instead of the actual web content

150,000 websites have been compromised by malicious JavaScript

This revelation comes as GoDaddy released details of a long-running malware operation called DollyWay World Domination , which has affected over 20,000 websites worldwide since 2016. As of February 2025, more than 10,000 unique WordPress websites have fallen victim to this scheme.

The attacks begin by injecting dynamically generated malicious JavaScript into the WordPress site, with the ultimate goal of redirecting visitors to VexTrio or LosPollos. It is also reported that this activity used advertising networks such as PropellerAds to exploit traffic from the compromised sites.

The malicious server-side injections are carried out via PHP code inserted into active plugins, while actions are taken to disable security plugins, delete malicious admin users, and steal legitimate admin credentials to achieve their goals.

See also: Phishing attack hides JavaScript using Unicode

GoDaddy revealed that DollyWay TDS exploits a distributed network of compromised WordPress sites as TDS and command and control (C2) nodes, reaching 9-10 million monthly page views. Additionally, VexTrio redirect URLs have been found to originate from the LosPollos traffic broker network.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS