SHARE
Facebook X Pinterest WhatsApp

Massive JSFireTruck Malware Campaign Infects Over 269,000 Websites

Over 269,000 websites have been compromised in a massive malware campaign using the obfuscated JSFireTruck script to stealthily redirect users to malicious sites.

Jun 16, 2025
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Security researchers have uncovered a large and growing cyberattack campaign that has infected hundreds of thousands of legitimate websites with malicious JavaScript code. 

The culprits behind this operation are using an obscure but powerful JavaScript obfuscation method dubbed JSFireTruck, a nickname coined by Palo Alto Networks’ Unit42 researchers.

At the heart of this campaign is an unusually disguised form of JavaScript that appears almost unreadable to the average developer. Instead of normal words and functions, the malicious code is constructed using a set of symbols: [, ], +, !, (, and ). These characters are manipulated using JavaScript’s own rules to recreate any code the attacker wants, without revealing the code’s real purpose.

How JSFireTruck works

Attackers inject this obfuscated JavaScript into trusted websites. The code appears strange and unreadable at first glance, often consisting of combinations like +[] and!.[], or ({}+[]). But beneath the mess lies a powerful script.

“The code’s obfuscation hides its true purpose, hindering analysis,” said researchers Hardik Shah, Brad Duncan, and Pranay Kumar Chhaparwal in a report by Unit 42.

The injected malicious code operates by checking the “document.referrer,” which essentially indicates the website from which a visitor came. If the referrer is a popular search engine such as Google, Bing, DuckDuckGo, Yahoo!, or AOL, the JSFireTruck redirects the victim to harmful URLs. 

These malicious destinations can lead to a variety of unwanted outcomes, including malware downloads, exploits, malvertising, and traffic monetization schemes. In some cases, the script loads an invisible iframe that covers the entire browser window, hiding the real website content and forcing users to interact with the attacker’s page instead.

The campaign’s deceptive nature means that a website might appear perfectly normal to a casual observer while secretly diverting a portion of its traffic to nefarious sites.

The scale of the JSFireTruck campaign is a major concern for cybersecurity experts. Between March 26 and April 25, 2025, Unit42 telemetry detected a staggering 269,552 webpages infected with this JavaScript code. A notable surge in activity was observed on April 12, when over 50,000 infected webpages were recorded in a single day.

“The campaign’s scale and stealth pose a significant threat,” the Unit42 researchers emphasized. “The widespread nature of these infections suggests a coordinated effort to compromise legitimate websites as attack vectors for further malicious activities.”

SEE: Quick Glossary: Malware (TechRepublic Premium)

How to stay protected

Experts warn that the silent nature of these attacks makes them particularly dangerous. Many website owners may not even know their sites are infected.

Unit42 recommends that web administrators regularly scan and update their websites, monitor for unexpected scripts, and use advanced security tools to detect obfuscated threats. Website owners should closely monitor traffic analytics and conduct regular audits of their web content for suspicious code, particularly if their sites heavily rely on third-party scripts or plugins.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

Recommended for you...

ClickFix Phishing Attacks Surge Nearly 400% in Just One Year
Matt Gonzales
Aug 19, 2025
AI Agents Vulnerable to ‘Silent Hijacking,’ Security Researchers Warn
Aminu Abdullahi
Aug 15, 2025
Cybersecurity Budget Growth Hits Five-Year Low as Economic Pressures Mount
Aminu Abdullahi
Aug 13, 2025
Inside Microsoft’s Real-Time War Against Cybersecurity Threats
Matt Gonzales
Aug 9, 2025
eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.