Malware
Cryptominer
Also called browser miner, cryptojacking.
Cryptominer is code that spends a victim's CPU or GPU hashing for cryptocurrency, with the proceeds going to the attacker. In browsers it appears as injected JavaScript or WebAssembly; on servers it is a hidden process.
How it is measured
Watch resource use. A page that holds a CPU core near 100 percent after it has finished loading, or a server process named `kdevtmpfsi` or `xmrig` that you did not install, is the sign. Outbound connections on mining pool ports such as 3333 or 4444, or to pool domains, confirm it.
For pages, search the source for WebAssembly modules, `Worker` spawns, and known miner libraries. Browser task manager shows per-tab CPU.
Worked example
A VPS hosting five WordPress sites slows to a crawl on Friday. `top` shows a process called `kswapd1` using 380 percent CPU, with a binary in `/tmp` that was written at 02:17. Its open connections point at a pool on port 3333.
The owner finds a stolen SSH password, kills the process, deletes the cron entry that restarts it, and changes credentials. Load drops from 11 to 0.4.
How it differs
A cryptominer is the category; Coinhive is one named browser miner that is now defunct. Miners differ from malware that steals data: they want your electricity and leave your files alone, so the harm shows up as heat, slowness, and a larger cloud bill. Cryptojacking is the usual name for doing it without consent.
Common errors
Blaming slowness on traffic. Killing the process but not the cron job or service that revives it. Looking only in the web root and missing `/tmp`. Assuming a miner means no other compromise. Disabling the script in one template and leaving the injected copy in the database.
In practice
Check CPU history on your servers for flat-topped usage that does not follow traffic. Review cron, systemd units, and the temp directories. If you find a miner, assume the way in is still open and rotate keys before restoring normal service.