Join our Newsletter — 33% off our NHI Course
Home› Glossary› Threats, Abuse & Incident Response› Browser-based Cryptojacking
Threats, Abuse & Incident Response

Browser-based Cryptojacking

← Back to Glossary
By NHI Mgmt Group Updated October 8, 2026 Domain: Threats, Abuse & Incident Response

Browser-based cryptojacking uses injected JavaScript or malicious ads to run mining code inside a visitor's browser session. It is usually temporary and session-bound, which makes page integrity and script monitoring more important than endpoint persistence checks.

What Browser-Based Cryptojacking Is

Browser-based cryptojacking is a session-bound abuse pattern, not a persistent host compromise. The attacker’s code runs only while the page stays loaded, so the core issue is malicious execution inside a trusted browsing context rather than long-term infection.

This makes the term useful for distinguishing client-side mining from broader malware categories. The browser becomes the execution environment, and the attack lives or dies on the integrity of delivered scripts, ads, and third-party content.

How the Attack Works

Most browser-based cryptojacking depends on injected JavaScript, compromised ad delivery, or another form of web platform scripting behavior that can start mining as soon as a visitor loads the page. The code usually tries to consume CPU cycles quietly, often throttling itself to avoid obvious browser slowdown.

Because it runs in the browser session, the attacker generally does not need a foothold on the endpoint itself. That makes it closer to content integrity abuse than to traditional endpoint malware persistence.

Why It Matters for Security Teams

The security concern is not just wasted processing power. Browser-based cryptojacking is also a signal that something in the content delivery chain, ad stack, or script inclusion model has been compromised or weakly governed.

That means the defender’s problem is often upstream of the browser. If a site allows unsafe third-party scripts, broad ad dependencies, or weak content controls, the same delivery path that enables mining can also enable credential theft, session abuse, or other malicious JavaScript activity.

For page-level control, browser-based cryptojacking aligns with broader integrity and monitoring concerns covered by NIST SP 800-53 Rev 5 Security and Privacy Controls, especially controls that address system integrity, logging, configuration, and access restrictions. It also sits naturally alongside OWASP API Security Top 10 when page logic depends on browser-to-backend calls that can be abused by injected client-side code.

Browser Integrity and Detection Signals

The practical detection problem is that browser-based mining can disappear when the user closes the tab, so endpoint tools focused only on installed malware may miss it. Security teams need to watch for unusual script sources, suspicious ad behavior, abnormal CPU usage tied to specific pages, and unexpected execution of third-party JavaScript.

Controls that reduce exposure usually focus on page integrity, script provenance, content security, and visibility into what the browser is allowed to load and execute. A useful way to think about the threat is that the browser session becomes the attack surface, and every untrusted script is a potential workload consumer.

Risk and Threat Considerations

Browser-based cryptojacking is risky because it can abuse a legitimate web session without leaving much persistence behind. That makes it attractive for attackers who want quiet, low-friction resource theft and who can survive by simply continuing to inject code through a compromised site or ad path.

Failure mechanism: Malicious JavaScript executes in the user’s browser, mines cryptocurrency with the victim’s CPU, and stops when the tab or session ends, which can hide the abuse from persistence-focused checks.

Impact: Organisations can see degraded user experience, higher resource consumption, and evidence that their script delivery or advertising chain has been compromised.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5SI-7 — Software, Firmware, and Information IntegrityBrowser-based cryptojacking depends on injected client-side code and integrity failure.
AU-2 — Event LoggingDetection depends on browser and page activity logs that reveal suspicious script execution.
Recommendation — Enforce integrity checks and script control to prevent untrusted browser execution. Log browser-relevant events and correlate them with anomalous resource consumption.
OWASP ASVSV13 — ConfigurationClient-side delivery and browser loading behavior are governed by secure configuration expectations.
Recommendation — Harden browser-delivered configuration and restrict unsafe third-party script inclusion.
MITRE ATT&CKT1055 — Process InjectionBrowser cryptojacking uses injected code inside an execution context to run attacker logic.
Recommendation — Map injected browser execution to attacker techniques and hunt for abnormal script execution.

Practitioner Guidance

What practitioners should watch for: Treat browser-based cryptojacking as a content-integrity problem first, then a performance problem. The most useful judgement is whether your site can load and execute third-party content without clear provenance, because that is often where the mining code enters.

Practitioner takeaway: If page integrity is weak, the browser can become an execution venue for abuse even when the endpoint itself looks clean.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org