CoffeeMiner is the latest in a series of capabilities that are designed to hijack innocent victim’s devices so they become unwitting miners of cryptocurrency for the attacker. The team over at Arnau Code ( posted a blog that outlines their academic effort to showcase how easy it is to hijack public wireless network hotspots and inject malicious javascript in html pages to force the systems to mine Monero coins for the benefit of the hacker.

The team provides a code breakdown of how they successfully created a Man-in-the-Middle (MITM) attack. It is a detailed proof-of-concept which shows a workable capability, but not refined code intended to do longstanding harm. The codebase, most Python, is available to the public.

In essence, an attacker armed with this code and some basic skills could sit at Starbucks and conduct the attack on unsuspecting victims who trust connecting to open WiFi access points. The victim’s systems would then mine cryptocurrency while browsing the Internet at that location. Truly malicious hackers could use this method to inject other types of malware on victim’s systems that could cause much more harm and persist long after they had left.

So beware when you connect to open WiFi networks, there may be someone ready to pounce on your gullibility.

