Browser-based cryptojacking uses injected JavaScript or malicious ads to run mining code inside a visitor's browser session. It is usually temporary and session-bound, which makes page integrity and script monitoring more important than endpoint persistence checks.
What Browser-Based Cryptojacking Is
Browser-based cryptojacking is a session-bound abuse pattern, not a persistent host compromise. The attacker’s code runs only while the page stays loaded, so the core issue is malicious execution inside a trusted browsing context rather than long-term infection.
This makes the term useful for distinguishing client-side mining from broader malware categories. The browser becomes the execution environment, and the attack lives or dies on the integrity of delivered scripts, ads, and third-party content.
How the Attack Works
Most browser-based cryptojacking depends on injected JavaScript, compromised ad delivery, or another form of web platform scripting behavior that can start mining as soon as a visitor loads the page. The code usually tries to consume CPU cycles quietly, often throttling itself to avoid obvious browser slowdown.
Because it runs in the browser session, the attacker generally does not need a foothold on the endpoint itself. That makes it closer to content integrity abuse than to traditional endpoint malware persistence.
Why It Matters for Security Teams
The security concern is not just wasted processing power. Browser-based cryptojacking is also a signal that something in the content delivery chain, ad stack, or script inclusion model has been compromised or weakly governed.
That means the defender’s problem is often upstream of the browser. If a site allows unsafe third-party scripts, broad ad dependencies, or weak content controls, the same delivery path that enables mining can also enable credential theft, session abuse, or other malicious JavaScript activity.
For page-level control, browser-based cryptojacking aligns with broader integrity and monitoring concerns covered by NIST SP 800-53 Rev 5 Security and Privacy Controls, especially controls that address system integrity, logging, configuration, and access restrictions. It also sits naturally alongside OWASP API Security Top 10 when page logic depends on browser-to-backend calls that can be abused by injected client-side code.
Browser Integrity and Detection Signals
The practical detection problem is that browser-based mining can disappear when the user closes the tab, so endpoint tools focused only on installed malware may miss it. Security teams need to watch for unusual script sources, suspicious ad behavior, abnormal CPU usage tied to specific pages, and unexpected execution of third-party JavaScript.
Controls that reduce exposure usually focus on page integrity, script provenance, content security, and visibility into what the browser is allowed to load and execute. A useful way to think about the threat is that the browser session becomes the attack surface, and every untrusted script is a potential workload consumer.
Risk and Threat Considerations
Browser-based cryptojacking is risky because it can abuse a legitimate web session without leaving much persistence behind. That makes it attractive for attackers who want quiet, low-friction resource theft and who can survive by simply continuing to inject code through a compromised site or ad path.
Failure mechanism: Malicious JavaScript executes in the user’s browser, mines cryptocurrency with the victim’s CPU, and stops when the tab or session ends, which can hide the abuse from persistence-focused checks.
Impact: Organisations can see degraded user experience, higher resource consumption, and evidence that their script delivery or advertising chain has been compromised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SI-7 — Software, Firmware, and Information Integrity | Browser-based cryptojacking depends on injected client-side code and integrity failure. |
| AU-2 — Event Logging | Detection depends on browser and page activity logs that reveal suspicious script execution. | |
| Recommendation — Enforce integrity checks and script control to prevent untrusted browser execution. Log browser-relevant events and correlate them with anomalous resource consumption. | ||
| OWASP ASVS | V13 — Configuration | Client-side delivery and browser loading behavior are governed by secure configuration expectations. |
| Recommendation — Harden browser-delivered configuration and restrict unsafe third-party script inclusion. | ||
| MITRE ATT&CK | T1055 — Process Injection | Browser cryptojacking uses injected code inside an execution context to run attacker logic. |
| Recommendation — Map injected browser execution to attacker techniques and hunt for abnormal script execution. | ||
Practitioner Guidance
What practitioners should watch for: Treat browser-based cryptojacking as a content-integrity problem first, then a performance problem. The most useful judgement is whether your site can load and execute third-party content without clear provenance, because that is often where the mining code enters.
Practitioner takeaway: If page integrity is weak, the browser can become an execution venue for abuse even when the endpoint itself looks clean.
Related resources from NHI Mgmt Group
- How should organisations reduce the risk of browser-based cryptojacking on unmanaged websites?
- What is the difference between browser-based cryptojacking and normal website scripting?
- How should security teams govern browser-based AI agents in SaaS environments?
- How should security teams govern browser-based AI prompts that may contain sensitive data?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org