All the latest UK technology news, reviews and analysis

Hackers found using Java malware on coding site after Google warning

25 Oct 2013
Online Piracy

Hackers have been found exploiting a flaw in Java to serve malware to unsuspecting web users on the open source server coding site

The issue came to light after visitors to the site started receiving notifications from Google's safe browsing service that malware was on the site. This alerted the team who investigated the cause of the warnings.

They discovered that every so often a file within the servers used for the website was modified to serve malware to a user, before it reverted back to its original form. This made it especially hard to discover the issue, and it was only found thanks to Google's scanning system.

Work is now beginning to try and discover how the hackers managed to infect the systems used to run the website.

"We are continuing to work through the repercussions of the malware issue. As part of this, the systems team has audited every server operated by, and have found that two servers were compromised," it said in a post on the website.

"The server which hosted the, and domains, and was previously suspected based on the JavaScript malware, and the server hosting The method by which these servers were compromised is unknown at this time."

Users of the site will also be asked to reset their passwords although the firm said this is only a precautionary measure for those with projects hosted within the services affected.

The website said it is also acquiring a new SSL certificate in case the attackers had acquired private keys for the site's security systems.

"We are in the process of getting a new certificate, and expect to restore access to sites that require SSL (including and in the next few hours," it said.

The use of Java for the attack is not surprising as the software has been blamed for numerous incidents throughout 2013 and was recently the subject of a huge patch update from Oracle.

  • Comment  
  • Tweet  
  • Google plus  
  • Facebook  
  • LinkedIn  
  • Stumble Upon  
Dan Worth

Dan Worth is the news editor for V3 having first joined the site as a reporter in November 2009. He specialises in a raft of areas including fixed and mobile telecoms, data protection, social media and government IT. Before joining V3 Dan covered communications technology, data handling and resilience in the emergency services sector on the BAPCO Journal

View Dan's Google+ profile

More on Security
What do you think?
blog comments powered by Disqus

Windows 7 end of mainstream support

What are your plans for when Microsoft ends mainstream support for Windows 7 in January 2015?

Popular Threads

Powered by Disqus
LG G3 in gold black and white

LG G3 vs Galaxy S5 video

We pit the two Korean firms' flagship smartphones against each other

Updating your subscription status Loading

Get the latest news (daily or weekly) direct to your inbox with V3 newsletters.

newsletter sign-up button

Getting started with virtualisation

Virtualisation can help you reduce costs, improve application availability, and simplify IT
management. However, getting started can be challenging


Converting big data and analytics insights into results

Successful leaders are infusing analytics throughout their organisations to drive smarter decisions, enable faster actions and optimise outcomes

Data Analyst - HR Focussed - Excel / VBA / Pivot

Based in Central Birmingham, we are looking for an experienced...


Redrock Consulting is currently looking for talented...

EPR PMO Support

EPR PMO Support- Manchester, 3 month contract- Part Time...

C# ASP.Net Developer - Crawley 30-40k+Bens

C# ASP.Net Developer - Crawley £30-40k+Bens One of...
To send to more than one email address, simply separate each address with a comma.