Accessibility plug-in Browsealoud was recently hacked, making thousands of websites use visitors’ systems to mine for cryptocurrency. The incident lasted just four hours until Texthelp temporarily shut down the tool. The ability to run arbitrary JavaScript in a browser session has the potential for far more potent attacks, such as collecting payment card details or stealing credentials from web-based forms. Security expert Troy Hunt: “Running a cryptominer was the simplest, most benign thing that could have been done””]
Source: https://www.cuinfosecurity.com/cryptocurrency-miners-how-to-shield-browsers-from-bad-guys-a-10651