Massive JSFireTruck Malware Campaign Infects Over 269,000 Websites

Over 269,000 websites have been compromised in a massive malware campaign using the obfuscated JSFireTruck script to stealthily redirect users to malicious sites.

Published: Jun 16, 2025
Updated: Jun 18, 2025
2 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Security researchers have uncovered a large and growing cyberattack campaign that has infected hundreds of thousands of legitimate websites with malicious JavaScript code. 

The culprits behind this operation are using an obscure but powerful JavaScript obfuscation method dubbed JSFireTruck, a nickname coined by Palo Alto Networks’ Unit42 researchers.

At the heart of this campaign is an unusually disguised form of JavaScript that appears almost unreadable to the average developer. Instead of normal words and functions, the malicious code is constructed using a set of symbols: [, ], +, !, (, and ). These characters are manipulated using JavaScript’s own rules to recreate any code the attacker wants, without revealing the code’s real purpose.

How JSFireTruck works

Attackers inject this obfuscated JavaScript into trusted websites. The code appears strange and unreadable at first glance, often consisting of combinations like +[] and!.[], or ({}+[]). But beneath the mess lies a powerful script.

“The code’s obfuscation hides its true purpose, hindering analysis,” said researchers Hardik Shah, Brad Duncan, and Pranay Kumar Chhaparwal in a report by Unit 42.

The injected malicious code operates by checking the “document.referrer,” which essentially indicates the website from which a visitor came. If the referrer is a popular search engine such as Google, Bing, DuckDuckGo, Yahoo!, or AOL, the JSFireTruck redirects the victim to harmful URLs. 

These malicious destinations can lead to a variety of unwanted outcomes, including malware downloads, exploits, malvertising, and traffic monetization schemes. In some cases, the script loads an invisible iframe that covers the entire browser window, hiding the real website content and forcing users to interact with the attacker’s page instead.

The campaign’s deceptive nature means that a website might appear perfectly normal to a casual observer while secretly diverting a portion of its traffic to nefarious sites.

The scale of the JSFireTruck campaign is a major concern for cybersecurity experts. Between March 26 and April 25, 2025, Unit42 telemetry detected a staggering 269,552 webpages infected with this JavaScript code. A notable surge in activity was observed on April 12, when over 50,000 infected webpages were recorded in a single day.

Advertisement

“The campaign’s scale and stealth pose a significant threat,” the Unit42 researchers emphasized. “The widespread nature of these infections suggests a coordinated effort to compromise legitimate websites as attack vectors for further malicious activities.”

SEE: Quick Glossary: Malware (TechRepublic Premium)

How to stay protected

Experts warn that the silent nature of these attacks makes them particularly dangerous. Many website owners may not even know their sites are infected.

Unit42 recommends that web administrators regularly scan and update their websites, monitor for unexpected scripts, and use advanced security tools to detect obfuscated threats. Website owners should closely monitor traffic analytics and conduct regular audits of their web content for suspicious code, particularly if their sites heavily rely on third-party scripts or plugins.

Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。