Malware

Coinhive

Coinhive is the name of a retired service that let website owners run a Monero miner in visitors' browsers instead of showing ads. It shut down in March 2019, but its script name and domain still appear in hacked sites and old threat lists.

How it is measured

Look for the loader URL `coinhive.com/lib/coinhive.min.js` or calls to `new CoinHive.Anonymous(...)`. A page with that script will peg a CPU core at high usage while the tab is open. Search page source and your theme files for the string `coinhive`.

A current hit is almost never intentional. The service is gone, so a surviving reference means leftover code, a copied snippet, or an attacker who reused the name. Scanners that match the Tarsier Threat Index flag the related hosts.

Worked example

A visitor reports that a church website makes their laptop fan spin. Inspecting the page source shows `<script src="https://coinhive.com/lib/coinhive.min.js">` followed by a start call with a site key, injected at the bottom of `footer.php`. The theme was last updated in 2018.

The volunteer webmaster removes the two lines, finds a backdoor file in the uploads folder, and cleans that too. CPU use on a test visit falls from about 95 percent to under 10.

How it differs

Coinhive is one named miner. A cryptominer is the broader category covering any code that mines coin on a machine that did not agree to it. Coinhive was sold as an opt-in business and then widely abused. Other miners use different domains and different loader scripts, so removing only the Coinhive string does not clear a miner infection.

Common errors

Assuming a dead service is a harmless leftover. Deleting the script tag but not the injected code that re-adds it. Searching only for the word `coinhive` and missing renamed copies such as `authedmine` or a base64 packed loader. Judging by page speed alone. Not checking the CMS for the entry point the attacker used.

In practice

Grep your theme, plugin, and database for `coinhive`, `authedmine`, and `CryptoNight`. Remove any hits, then ask how they got in, since the attacker found a way to edit your files. Patch that, rotate admin passwords, and check CPU usage on a clean visit.

See also

Cryptominer, Tarsier Threat Index

Sources

Count this on a real site.

Watch my website