This post is part of our research archive and is a selected publication. Although Armatyr was founded in 2026, members of our team have been conducting and publishing research in medical device and hospital IT security for over a decade. We maintain this archive to provide context for our experience and contributions to the field.

The authors show how HTML5 Web Workers can be abused to perform stealthy computation and establish covert communication channels inside a victim’s browser, without the user’s knowledge. Because Web Workers run in the background with no visible indication to the user, a malicious script can spawn them to crack passwords, exhaust system resources, or exfiltrate data while the browser appears idle. The authors demonstrate a working password cracker and denial-of-service attack built entirely on this technique, then propose mitigations to make worker activity visible to users. In a dedicated appendix, they run the same denial-of-service attack against a Baxa ExactaMix, a real embedded medical compounding device used to mix IV nutrition solutions, and show it drives the device’s memory and swap usage into a sustained spike — a concrete demonstration that a browser-only web attack can degrade a networked medical device. Their full abstract is quoted below:

JavaScript execution and UI rendering are typically single-threaded; thus, the execution of some scripts can block the display of requested content to the browser screen. Web Workers is an API that enables web applications to spawn background workers in parallel to the main page. Despite the usefulness of concurrency, users are unaware of worker execution, intent, and impact on system resources. We show that workers can be used to abuse system resources by implementing a unique denial-of-service attack and resource depletion attack. We also show that workers can be used to perform stealthy computation and create covert channels. We discuss potential mitigations and implement a preliminary solution to increase user awareness of worker execution.

Michael Rushanan, David Russell, and Aviel D. Rubin. “MalloryWorker: Stealthy Computation and Covert Channels using Web Workers.” Proceedings of International Workshop on Security and Trust Management (STM), 2016.