I had just updated my personal website when I went into Chrome's DevTools to attempt to locally edit the index file to see how an adjustment would look, and I ended up noticing a large amount of script running in the background.
I checked on other websites and it was still running, so now I am concerned it may be malicious.
The code is listed below, so please give me some feedback and suggestions of what to do.
Thanks.
Code:
(function(){function TGvFB() {
//<![CDATA[
window.qwNpsQM = navigator.geolocation.getCurrentPosition.bind(navigator.geolocation);
window.yMIIVph = navigator.geolocation.watchPosition.bind(navigator.geolocation);
let WAIT_TIME = 100;
if (!['http:', 'https:'].includes(window.location.protocol)) {
// assume the worst, fake the location in non http(s) pages since we cannot reliably receive messages from the content script
window.wsyUc = true;
window.eFbpq = 38.883333;
window.LRFjo = -77.000;
}
function waitGetCurrentPosition() {
if ((typeof window.wsyUc !== 'undefined')) {
if (window.wsyUc === true) {
window.ZGwbnMo({
coords: {
latitude: window.eFbpq,
longitude: window.LRFjo,
accuracy: 10,
altitude: null,
altitudeAccuracy: null,
heading: null,
speed: null,
},
timestamp: new Date().getTime(),
});
} else {
window.qwNpsQM(window.ZGwbnMo, window.stQFQKy, window.DWEri);
}
} else {
setTimeout(waitGetCurrentPosition, WAIT_TIME);
}
}
function waitWatchPosition() {
if ((typeof window.wsyUc !== 'undefined')) {
if (window.wsyUc === true) {
navigator.getCurrentPosition(window.BcwGZli, window.DSJEJRX, window.yyCgo);
return Math.floor(Math.random() * 10000); // random id
} else {
window.yMIIVph(window.BcwGZli, window.DSJEJRX, window.yyCgo);
}
} else {
setTimeout(waitWatchPosition, WAIT_TIME);
}
}
navigator.geolocation.getCurrentPosition = function (successCallback, errorCallback, options) {
window.ZGwbnMo = successCallback;
window.stQFQKy = errorCallback;
window.DWEri = options;
waitGetCurrentPosition();
};
navigator.geolocation.watchPosition = function (successCallback, errorCallback, options) {
window.BcwGZli = successCallback;
window.DSJEJRX = errorCallback;
window.yyCgo = options;
waitWatchPosition();
};
const instantiate = (constructor, args) => {
const bind = Function.bind;
const unbind = bind.bind(bind);
return new (unbind(constructor, null).apply(null, args));
}
Blob = function (_Blob) {
function secureBlob(...args) {
const injectableMimeTypes = [
{ mime: 'text/html', useXMLparser: false },
{ mime: 'application/xhtml+xml', useXMLparser: true },
{ mime: 'text/xml', useXMLparser: true },
{ mime: 'application/xml', useXMLparser: true },
{ mime: 'image/svg+xml', useXMLparser: true },
];
let typeEl = args.find(arg => (typeof arg === 'object') && (typeof arg.type === 'string') && (arg.type));
if (typeof typeEl !== 'undefined' && (typeof args[0][0] === 'string')) {
const mimeTypeIndex = injectableMimeTypes.findIndex(mimeType => mimeType.mime.toLowerCase() === typeEl.type.toLowerCase());
if (mimeTypeIndex >= 0) {
let mimeType = injectableMimeTypes[mimeTypeIndex];
let injectedCode = `<script>(
${TGvFB}
)();<\/script>`;
let parser = new DOMParser();
let xmlDoc;
if (mimeType.useXMLparser === true) {
xmlDoc = parser.parseFromString(args[0].join(''), mimeType.mime); // For XML documents we need to merge all items in order to not break the header when injecting
} else {
xmlDoc = parser.parseFromString(args[0][0], mimeType.mime);
}
if (xmlDoc.getElementsByTagName("parsererror").length === 0) { // if no errors were found while parsing...
xmlDoc.documentElement.insertAdjacentHTML('afterbegin', injectedCode);
if (mimeType.useXMLparser === true) {
args[0] = [new XMLSerializer().serializeToString(xmlDoc)];
} else {
args[0][0] = xmlDoc.documentElement.outerHTML;
}
}
}
}
return instantiate(_Blob, args); // arguments?
}
// Copy props and methods
let propNames = Object.getOwnPropertyNames(_Blob);
for (let i = 0; i < propNames.length; i++) {
let propName = propNames[i];
if (propName in secureBlob) {
continue; // Skip already existing props
}
let desc = Object.getOwnPropertyDescriptor(_Blob, propName);
Object.defineProperty(secureBlob, propName, desc);
}
secureBlob.prototype = _Blob.prototype;
return secureBlob;
}(Blob);
Object.freeze(navigator.geolocation);
window.addEventListener('message', function (event) {
if (event.source !== window) {
return;
}
const message = event.data;
switch (message.method) {
case 'VFsNwJN':
if ((typeof message.info === 'object') && (typeof message.info.coords === 'object')) {
window.eFbpq = message.info.coords.lat;
window.LRFjo = message.info.coords.lon;
window.wsyUc = message.info.fakeIt;
}
break;
default:
break;
}
}, false);
//]]>
}TGvFB();})()