Northern Advocate
  • Northern Advocate home
  • Latest news
  • Business
  • Opinion
  • Lifestyle
  • Sport
  • Property
  • Video
  • Death notices
  • Classifieds

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • On The Up
  • Business
  • Opinion
  • Lifestyle
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
  • Sport
  • Property
    • All Property
    • Residential property listings

Locations

  • Far North
  • Kaitaia
  • Kaikohe
  • Bay of Islands
  • Whangārei
  • Kaipara
  • Mangawhai
  • Dargaville

Media

  • Video
  • Photo galleries
  • Today's Paper - E-Editions
  • Photo sales
  • Classifieds

Weather

  • Kaitaia
  • Whangārei
  • Dargaville

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Northern Advocate

Porirua City Council and Whangarei District Council websites cryptojacked in international cyber attack

By Chris Knox & Melissa Nightingale
NZ Herald·
14 Feb, 2018 12:41 AM4 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Hackers hit more than 4000 websites around the world, injecting a crypto mining code into scripts being used on their sites. Photo / 123RF

Hackers hit more than 4000 websites around the world, injecting a crypto mining code into scripts being used on their sites. Photo / 123RF

At least two council websites fell victim to cryptojackers last weekend without anybody realising, leaving visitors to the sites unwittingly helping hackers mine for cryptocurrency.

The Porirua City Council and Whangarei District Council are among several thousand sites internationally that were caught up in what Netsafe has called a "benign" attack.

Porirua City Council's chief information officer Steve McIntosh said the website itself was not compromised. But anyone visiting the site during the attack downloaded malicious code without realising it.

On Sunday, 4275 websites, including the US Courts site and the UK's Information Commissioner's Office site were running a script that had been altered to add a Coinhive crypto miner to any page it was loaded into.

"People who visited that website over the weekend, they would have seen their CPU, the brains of their computers, spike up to an enormous amount of activity suddenly," said Netsafe's director of technology Sean Lyons.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Hey @texthelp you've been compromised, you need to address this ASAP. Their site also has the crypto miner running: pic.twitter.com/fl0U9ssZRr

— Scott Helme (@Scott_Helme) February 11, 2018

"They were being used to mine cryptocurrency without their knowledge, without their host's knowledge."

The practice is called "cryptojacking" and is when hackers use people's computers to "build small parts of cryptocurrency" such as Bitcoin.

The hack was "at the benign end of what could happen".

Advertisement
Advertise with NZME.

"What people are doing is they're using your processing power, they're using your computer, albeit for a short space of time, as part of a giant hive of computers to help them generate money."

Visitors to the Porirua City Council website on Sunday may have noticed their devices were running slower as they mined for cryptocurrency, similar to Bitcoin. Photo / 123RF
Visitors to the Porirua City Council website on Sunday may have noticed their devices were running slower as they mined for cryptocurrency, similar to Bitcoin. Photo / 123RF

Affected people would discover their devices were running "massively slow" while they were on the site.

"Often people wouldn't notice. People would just say 'I wonder why my fans have started running' or 'I wonder why my computer's slowed down'."

In theory if they stayed on the site long enough their CPU could overheat and cause physical damage to the computer, but that was unlikely, he said.

After being contacted by the Herald, a council spokeswoman said on Tuesday that as far as they were aware, the website had not been cryptojacked.

But screenshots show the site was still running the compromised script yesterday, a text-to-speech accessibility script called BrowseAloud by TextHelp.com. Security researcher Scott Helme posted on Twitter, saying it appeared the script was altered between about 3am and 1.20pm on Sunday (GMT).

The script was no longer on the council site this morning.

It seems like the @texthelp script file was modified between Sun, 11 Feb 2018 02:58:04 GMT and Sun, 11 Feb 2018 13:21:56 GMT according to the @internetarchive:https://t.co/jwKLA6mq7Nhttps://t.co/ZHiUJXBpxC

— Scott Helme (@Scott_Helme) February 11, 2018

"Our website was not compromised in any way," McIntosh said in a statement.

"We were using the third party plugin BrowseAloud to enable people with sight impairments to 'read' our site. BrowseAloud converts website text to audio. Customers who used this plugin load it directly from the Browsealoud website not the Porirua City Council website."

The Whangarei District Council, which is still running the script, has been contacted for comment.

Advertisement
Advertise with NZME.

Lyons said this type of hack was sometimes referred to as a "drive-by exploit", when visitors to the site went there for something else but ended up being harmed by something else in the process.

"There are ways to stop these kinds of exploits but it does take time and it does take resource to do that, so sometimes we know when things do slip through ... you find yourself in situations where you put yourselves and the people who use your website potentially in harm's way."

If websites had "holes" and vulnerabilities that allowed such things to happen, then "the world's your oyster as far as the hacker's concerned".

Screenshots show the affected ba.js script still being used on the Porirua City Council website on Tuesday. Image / Chris Knox
Screenshots show the affected ba.js script still being used on the Porirua City Council website on Tuesday. Image / Chris Knox

"They could be at that point trying to put similar software on your computer that causes a chain reaction across the internet."

Hackers could potentially dig for sensitive details including names, passwords, logins, emails, or, on the more serious end, driver's licence details, passport numbers, and bank details.

Anyone using their banking details on the council website was not at risk from the vulnerability, though, as the parts of the site used for payments were hosted elsewhere.

Advertisement
Advertise with NZME.

Lyons said people managing public websites should run firewalls and run systems on the servers, and these would stop 99 per cent of attacks.

In a statement released on Sunday, the third party provider Texthelp confirmed their BrowseAloud script had been compromised in a cyber attack.

"The attacker added malicious code to the file to use the browser CPU in an attempt to illegally generate cryptocurrency. This was a criminal act," said chief technology officer Martin McKay in the statement.

"Texthelp is working with the National Crime Agency and The National Cyber Security Centre to pursue the investigation further."

Save

    Share this article

Latest from Northern Advocate

Northern Advocate

Three bidders confirmed for Northland Expressway PPP

21 Jun 05:00 PM
Northern Advocate

'I wouldn't wish it on anyone': Why are victims having to wait until 2027 for justice?

21 Jun 01:00 AM
Premium
Opinion

Opinion: Endless tourist tours are our modern purgatory

20 Jun 05:00 PM

Jono and Ben brew up a tea-fuelled adventure in Sri Lanka

sponsored
Advertisement
Advertise with NZME.

Latest from Northern Advocate

Three bidders confirmed for Northland Expressway PPP

Three bidders confirmed for Northland Expressway PPP

21 Jun 05:00 PM

Initial construction work on the next section is set to begin by the end of next year.

'I wouldn't wish it on anyone': Why are victims having to wait until 2027 for justice?

'I wouldn't wish it on anyone': Why are victims having to wait until 2027 for justice?

21 Jun 01:00 AM
Premium
Opinion: Endless tourist tours are our modern purgatory

Opinion: Endless tourist tours are our modern purgatory

20 Jun 05:00 PM
Why kiwi deaths on roads highlight a conservation success story

Why kiwi deaths on roads highlight a conservation success story

20 Jun 02:00 AM
Help for those helping hardest-hit
sponsored

Help for those helping hardest-hit

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • The Northern Advocate e-edition
  • Manage your print subscription
  • Manage your digital subscription
  • Subscribe to Herald Premium
  • Subscribe to the Northern Advocate
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The Northern Advocate
  • The New Zealand Herald
  • The Northland Age
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • © Copyright 2025 NZME Publishing Limited
TOP