A sophisticated client-side JavaScript attack has compromised over 500 websites, including high-profile government and university domains.
The malicious campaign, which injects hidden links into the Document Object Model (DOM), is believed to be part of a black hat Search Engine Optimization (SEO) effort to manipulate search engine rankings.
According to Cside researchers the attack involves the injection of JavaScript hosted on the domain scriptapi[.]dev. The scripts generate invisible links pointing to external websites, leveraging reputable domains to boost the SEO value of these external sites.
These links are styled using CSS to remain hidden from users:
The malicious scripts are distributed across multiple endpoints, including:
The c/side researchers identified the malicious domain on January 20, 2025, but no major threat feeds have flagged it yet.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free
The attack operates in two primary steps:
These hidden links are indexed by search engines, attributing SEO value to external sites without user visibility or awareness.
The attack targets a wide range of websites using various frameworks, highlighting its broad applicability. Affected platforms include:
To protect against such attacks, organizations should implement robust security measures:
This JavaScript attack highlights the persistent threat posed by black hat SEO campaigns and supply chain vulnerabilities in web development.
Organizations must adopt proactive measures like CSP, SRI, and regular audits to safeguard their digital assets against such sophisticated threats.
Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar
In an unprecedented cybersecurity incident that occurred in September 2025, over 500 gigabytes of internal…
WhatsApp has unveiled passkey-encrypted backups, simplifying the protection of cherished chat histories without the burden…
A sophisticated Linux kernel rootkit designed to slip past the defenses of Elastic Security, a…
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-41244 to its Known Exploited Vulnerabilities…
Researchers have uncovered a sophisticated campaign leveraging the Lampion banking trojan, a malware strain that…
A new agent-aware cloaking technique uses AI browsers like OpenAI's ChatGPT Atlas to deliver misleading…