What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Palo Alto Networks Unit 42 recorded 269,552 infected web pages from March 26 through April 25, 2025. That is a telemetry count of pages—not a verified count of unique websites, domains, or owners. The campaign used heavily obfuscated JavaScript to conceal code that could selectively redirect some visitors, including people arriving from search engines.

What is JSFireTruck?

JSFireTruck is the name used for an obfuscated JavaScript technique based on JSFuck, a style of writing JavaScript with a restricted set of characters. In the reported campaign, injected code used JavaScript behavior to hide and reconstruct instructions, making its purpose harder to recognize during analysis. The name describes the obfuscation approach reported in the incident; it does not by itself identify a particular website platform or a confirmed point of entry.

Unit 42 researchers Hardik Shah, Brad Duncan, and Pranay Kumar Chhaparwal said: “The code’s obfuscation hides its true purpose, hindering analysis.”

How many websites were infected?

Unit 42 telemetry detected 269,552 infected web pages between March 26 and April 25, 2025, according to The Hacker News’ June 13, 2025 report. The measurement is pages, so it should not be presented as 269,552 distinct websites or organizations: one site can contain multiple pages, and the reporting does not establish a unique-domain total.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Unit 42 also recorded more than 50,000 infected web pages on April 12, 2025, a one-day spike during that observation period. The reported sources do not provide an independently verified total for victim organizations, financial losses, or confirmed downstream infections.

How did the malicious JavaScript work?

The injected script could inspect document.referrer, the browser value that indicates the page or source from which a visitor arrived. When that source was a search engine, some variants could redirect the visitor to a malicious destination. This conditional behavior could make the activity less obvious to site owners who visited a page directly rather than through search results.

Reported possible destinations and effects included malware, exploit pages, phishing pages, and traffic monetization or malvertising. Some variants could also place a hidden iframe over the legitimate page. These are reported capabilities and outcomes, not a claim that every infected page redirected every visitor or produced all of these effects.

Coverage also discusses HelloTDS, a traffic distribution service that can route selected visitors to scams and fake prompts. It is related threat context; the reporting does not establish that HelloTDS and JSFireTruck were the same campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What caused the infections?

The available incident reporting establishes that malicious scripts were injected into legitimate pages, but it does not confirm a single initial access method, exploited vulnerability, affected content management system, or implicated plugin. It is therefore not supported to attribute the campaign to a specific WordPress flaw or plugin. The script’s behavior after reaching a page is better documented than how each site was compromised.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should website owners do?

Unit 42 guidance reported by eSecurity Planet recommends general defensive practices. These steps can help administrators look for suspicious changes and reduce exposure, but the reporting does not show that any single tool or control would have prevented or removed this particular campaign.

  • Scan and update regularly. Include the website and its components in a routine maintenance and security review.
  • Monitor for unexpected scripts. Investigate scripts that appear without an approved change, especially obfuscated code or modifications to legitimate pages.
  • Use security tools that can detect obfuscated threats. Treat alerts as leads to investigate rather than proof of a specific infection.
  • Audit site content and third-party code. Review page content and the scripts, plugins, and other external components the site relies on.

If an unexpected script is found, preserve relevant evidence and investigate how it was added before removing it; otherwise, the underlying access path may remain. The incident sources do not provide a campaign-specific cleanup procedure or identify one universal remediation product.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.